Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-31 and was added to the RWP archive on 2026-09-07.

Daily Top · Nation-State

CaptiveCrunch put Midnight Blizzard on hotel sign-in pages — the traveler was the payload path

Microsoft tracks Storm-2945, a Midnight Blizzard sub-cluster, compromising hospitality portals since May 2026 to drop malware and steal credentials from guests.

RWP Ventures · 2026-09-07 · event 2026-05-01 · 1 min read · priority 8.5

Bottom line up front

CONFIRMED Microsoft 31 July 2026 — operation CaptiveCrunch. Storm-2945, sub-cluster of Midnight Blizzard (Russia), observed since May 2026 compromising sign-in portals of hospitality organizations (hotels) to deliver malware to travelers and steal credentials. Collection against people in transit, not a hotel-ICS claim. Distinct from Forest Blizzard SOHO DNS and Secret Blizzard Kazuar — do not merge Russian clusters. Process/OT at the property: UNKNOWN / not evidenced.

Historical backfill of 31 July 2026 reporting; added 7 September 2026.

What happened

The captive portal and hotel Wi-Fi login are trusted enough that a diplomat or executive will type a password. Compromising the portal is cheaper than phishing the executive's corporate mail.

Why it mattered

Travel is an identity bypass. Conditional access that trusts "hotel network" plus a poisoned portal is how you steal the session without a 0-day on the laptop.

Who / what was affected

Hospitality portals; travelers as downstream victims. Named victim hotels not required for the assessment.

Technical context

Travelers: prefer known-good VPN before any portal, phishing-resistant MFA, never install "network helper" from a hotel page. Hotels: integrity monitoring on IdP/portal, no extra JS from random CDNs.

Exploitation / threat status at the time

CONFIRMED Microsoft attribution and targeting.

UNKNOWN full victim list.

What defenders should have done

  1. Executive travel advisory in May–July 2026 and after.
  2. Hospitality sector: treat guest sign-in as tier-0.
  3. Hunt unexpected JS on portal pages.

RWP assessment

Confidence: High on Microsoft's cluster naming. Hotels are SIGINT-adjacent.

Defensive actions

  1. Travel kit: hardware key, no portal installs.
  2. SOC rule: hospitality-sector portal defacement/JS change.
  3. Do not call this OT because the building has HVAC.

Sources

  1. Microsoft — CaptiveCrunch: Midnight Blizzard targets travelers
  2. Microsoft — Forest Blizzard SOHO DNS (related GRU collection, different cluster)
  3. Microsoft — Kazuar / Secret Blizzard (different FSB cluster)