Microsoft Threat Intelligence has identified a specific campaign, dubbed CaptiveCrunch, where Russian state-sponsored hackers are compromising hotel Wi-Fi portals to target travelers' Microsoft 365 accounts. The activity, disclosed in Microsoft's threat intelligence reporting, is attributed to Storm-2945, a sub-cluster within the notorious Midnight Blizzard group—also known as APT29 and Cozy Bear—which operates under Russia's SVR.
Since early May 2026, Storm-2945 operators have been manipulating DNS responses related to hotel captive portals. This technique redirects guests who connect to seemingly legitimate hotel Wi-Fi networks, leading them to malicious infrastructure. Here, malware is deployed to harvest Microsoft 365 authentication tokens directly from users' browsers and sessions.
This method of theft is particularly dangerous because Microsoft 365 tokens are long-lived bearer credentials. If stolen, they grant attackers persistent access to a victim's email, files, and collaboration data without triggering further password or MFA prompts. For enterprises with frequent travelers, this creates a high-risk exposure point at the network edge, where devices connect outside traditional security perimeters.
The campaign fits within APT29's established playbook of opportunistic access followed by cloud identity abuse. Historically focused on intelligence gathering from governments and policy institutes, the group is now leveraging common travel infrastructure to cast a wider net for high-value cloud access.
Microsoft's advisory emphasizes concrete defensive measures. Organizations should prioritize token lifecycle management, implementing policies for shorter refresh token lifetimes and continuous access evaluation. Travel device policies should enforce secure routing for sensitive traffic, and IT teams should audit captive portal configurations on managed devices. Conditional access policies that check device compliance and risk signals are critical to blocking stolen token use.
The disclosure underscores that even ubiquitous public Wi-Fi remains a potent attack vector. For IT professionals managing Microsoft 365 environments, the key takeaway is the need to protect session tokens as vigorously as passwords, applying layered controls to mitigate the risk of compromise during legitimate business travel.
微軟威脅情報部門識別出名為「CaptiveCrunch」的專項攻擊活動,俄羅斯國家支持的黑客正入侵酒店Wi-Fi登入門戶,以鎖定旅客的Microsoft 365帳戶。根據微軟威脅情報報告披露,此活動歸因於Storm-2945——這是臭名昭著的Midnight Blizzard組織(又稱APT29及Cozy Bear)的子集群,該組織隸屬於俄羅斯對外情報局(SVR)運作體系。
自2026年5月初以來,Storm-2945操作員持續篡改與酒店強制登入門戶相關的DNS回應。此技術會將連接看似合法酒店Wi-Fi網絡的旅客,重定向至惡意基礎設施。在此過程中,惡意軟件會被部署,直接從用戶的瀏覽器及會話中竊取Microsoft 365驗證令牌。
此竊取手法極具危險性,因為Microsoft 365令牌屬於長效期的持有者憑證。一旦被盜,攻擊者可無需觸發後續密碼或多因素驗證(MFA)提示,便能持續存取受害者的電郵、檔案及協作數據。對於頻繁有員工外勤的企業而言,這在網絡邊緣設備連接傳統安全範圍之外時,構成高風險暴露點。
此攻擊行動符合APT29慣用的機會主義存取模式,繼而濫用雲端身份驗證機制。該組織歷來專注於針對政府及政策研究機構的情報蒐集,現正利用普遍存在的旅行基礎設施,擴大對高價值雲端存取權的監控範圍。
微軟的通告強調具體防禦措施。企業應優先處理令牌生命週期管理,實施縮短刷新令牌有效期及持續存取評估等策略。外出設備政策應強制敏感流量使用安全路由,IT團隊需審計受管設備的強制登入門戶配置。檢查設備合規性及風險信號的條件存取政策,對阻截被盜令牌的使用至關重要。
此次披露再次確認,即使無處不在的公共Wi-Fi仍是一條強而有力的攻擊途徑。對於管理Microsoft 365環境的IT專業人員而言,核心要點在於必須以同等嚴謹程度保護會話令牌與密碼,並透過分層控制措施降低合法商務旅行期間的入侵風險。
