Actor Profile
Storm-2945 is an operational sub-cluster of Midnight Blizzard (APT29), a Russia-based threat actor attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR). The actor conducts longstanding espionage operations in support of Russian foreign policy interests, primarily targeting governments, diplomatic entities, NGOs, and IT service providers in the US and Europe. Storm-2945 shares technical and operational overlaps with Storm-2372, another Midnight Blizzard sub-cluster known for device code and OAuth phishing operations. The actor has demonstrated capability to leverage AI to augment operational activities and employs sophisticated traffic manipulation techniques to compromise valid accounts and authentication mechanisms.
TTPs (Tactics, Techniques, Procedures)
Storm-2945 employs traffic manipulation attacks via compromised captive portal infrastructure (T1621 - Adversary-in-the-Middle), conducting DNS and HTTP redirection through actor-controlled infrastructure. The actor delivers Golang-based Windows RATs using ClickFix social engineering techniques, with capabilities including credential theft (T1003.002 - Security Account Manager), data collection (T1005 - Data from Local System), keylogging, audio/video surveillance, removable media monitoring, and remote shell access (T1105 - Ingress Tool Transfer). Initial access leverages device code and OAuth code phishing campaigns abusing Microsoft Entra ID authentication flows (T1528 - Steal Application Access Token), leading to Entra device registration and Microsoft 365 data exfiltration. The actor utilizes doppelganger domains (T1588.002 - Tool) mimicking Microsoft services, Microsoft Graph-based email exfiltration, and social engineering via commercial messaging apps. Activity includes potential Android device targeting via malicious APK delivery.
Targets & Patterns
Storm-2945 targets corporate travelers through widespread compromise of Wi-Fi networks at hospitality-related organizations including hotels, conference centers, and shared venues serviced by captive portal equipment across multiple countries. The targeting pattern suggests focus on accessing accounts of business travelers from government, diplomatic, NGO, and IT service provider sectors—consistent with Midnight Blizzard's traditional victimology. The actor exploits commonalities in captive portal equipment and management systems across affected networks, suggesting potential access to shared services within the captive portal ecosystem rather than isolated venue compromises. Geographic focus remains primarily US and Europe, aligned with SVR intelligence collection priorities supporting Russian foreign policy interests.
Historical Context
Storm-2945 activity builds on Midnight Blizzard's established operational patterns, with technical similarities to Storm-2372 device code and OAuth phishing campaigns tracked throughout 2025. The CaptiveCrunch campaign shares TTP similarities with the Forest Blizzard DNS hijacking operation publicly disclosed in April 2026, though Microsoft attributes CaptiveCrunch distinctly to Storm-2945. Since February 2026, Storm-2945 has conducted AI-augmented operations including targeted device code phishing leading to Entra device registration and Microsoft 365 data collection. The May 2026 shift to captive portal manipulation represents an evolution in initial access methodology while maintaining consistent focus on credential theft and intelligence collection. Midnight Blizzard (APT29/IRON RITUAL/NobleBaron/Dark Halo) has historical associations with malware families including PinchDuke, WellMail, CozyCar, EnvyScout, and SoreFang.
Defensive Recommendations
- Monitor for anomalous device code authentication flows (T1528) and unexpected Entra ID device registrations, particularly from hospitality/travel network IP ranges; implement conditional access policies requiring compliant devices
- Deploy network monitoring to detect DNS manipulation and HTTP traffic redirection patterns (T1621) on captive portal infrastructure; validate DNS responses against authoritative sources and implement DNSSEC where possible
- Block execution of unsigned or suspicious Golang binaries; monitor for ClickFix-style social engineering prompts requesting manual PowerShell or command-line execution; enable Attack Surface Reduction rules to block untrusted executable content
- Implement enhanced logging for credential access attempts (T1003.002) via Sysmon Event IDs 10 (process access) targeting lsass.exe and Event ID 1 (process creation) for suspicious enumeration tools; alert on Microsoft Graph API calls with unusual data exfiltration patterns
- Educate travelers on risks of untrusted Wi-Fi networks; enforce VPN usage on hospitality networks; scrutinize unexpected browser/OS update prompts, especially those requiring manual installation steps or APK downloads on Android devices
---
# Geopolitical Context
Geopolitical Context
The CaptiveCrunch campaign represents an evolution in Russian foreign intelligence tradecraft, targeting the hospitality sector to exploit a persistent vulnerability in modern espionage: business travelers accessing corporate resources over shared networks. Storm-2945, assessed to be a sub-cluster of Midnight Blizzard (attributed by US and UK governments to Russia's Foreign Intelligence Service, the SVR), has since May 2026 compromised captive portal infrastructure at hotels and conference centers globally. The operation appears consistent with SVR's longstanding mandate to collect strategic intelligence in support of Russian foreign policy objectives, particularly from government, diplomatic, NGO, and IT sector personnel. The campaign's sophistication—including AI-augmented operations, adversary-in-the-middle phishing, device code abuse, and cross-platform malware delivery—reflects continued Russian investment in technical collection capabilities despite Western sanctions and attribution efforts. The targeting of corporate travelers at hospitality venues suggests an intent to circumvent hardened enterprise perimeters by exploiting the trusted-but-vulnerable moment when targets authenticate to cloud services from transient networks.
State Actor Alignment
Storm-2945 is assessed by Microsoft Threat Intelligence to be an operational sub-cluster of Midnight Blizzard, which the US and UK governments have attributed to Russia's Foreign Intelligence Service (SVR). The campaign aligns with established SVR priorities: intelligence collection from governments, diplomatic entities, NGOs, and IT service providers, primarily in the US and Europe. The operational continuity with Storm-2372—another Midnight Blizzard sub-cluster active in 2025—and the focus on credential theft and long-term access are consistent with state-sponsored espionage rather than financially motivated cybercrime. The use of AI to augment operations and the global scope of captive portal compromises suggest significant resource investment characteristic of a well-funded intelligence service. This activity occurs against a backdrop of sustained Western sanctions on Russia and ongoing efforts to disrupt SVR cyber operations, yet demonstrates persistent capability and adaptability.
Business Impacty pro region
The campaign has global reach, with compromised Wi-Fi networks identified at hospitality venues in multiple countries, though Microsoft's reporting emphasizes US and European targeting consistent with SVR intelligence priorities. For Europe, the operation poses acute risk: European capitals host concentrations of diplomatic missions, international organizations, and policy institutions whose personnel frequently travel and use hotel networks. The compromise of conference centers is particularly concerning for venues hosting security policy dialogues, NATO-related events, or EU institutional meetings. The campaign also threatens transatlantic coordination, as compromised credentials could enable follow-on access to sensitive government and contractor networks. For countries hosting international summits or multilateral negotiations, the risk extends beyond individual account compromise to potential intelligence collection on policy deliberations. The reliance on shared captive portal infrastructure suggests that smaller nations with less robust cybersecurity ecosystems may face disproportionate exposure. The campaign underscores the inadequacy of perimeter-based security models in an era of cloud authentication and remote work, with implications for how allied governments secure mobile workforces.
Forecast
If Storm-2945 maintains access to captive portal infrastructure or shared management systems, the campaign is likely to persist through 2026 and potentially expand to additional hospitality and venue networks globally. Increased public disclosure and defensive measures may prompt tactical shifts—such as changes in malware delivery mechanisms or phishing templates—but are unlikely to alter the underlying operational objective of credential harvesting from high-value travelers. If Western governments impose additional sanctions or conduct disruptive cyber operations against SVR infrastructure, Storm-2945 may temporarily reduce operational tempo or shift to alternative initial access vectors, though historical patterns suggest sustained SVR commitment to espionage campaigns despite attribution. If the initial compromise vector involves shared services within the captive portal ecosystem (as Microsoft's investigation suggests), remediation may require coordinated action across multiple vendors and venue operators, potentially prolonging exposure windows. Organizations that implement phishing-resistant authentication (such as FIDO2 hardware tokens) and enforce conditional access policies restricting device registration are likely to significantly reduce their risk profile. If AI-augmented operations prove effective, other state-sponsored threat actors may adopt similar techniques, potentially increasing the volume and sophistication of credential phishing campaigns targeting mobile workforces in the coming months.
