A hacking campaign targeting the hospitality sector through hijacked network login pages and abuse of Microsoft Entra ID is showing fresh activity, two months after Microsoft first flagged the attacks.
The CaptiveCrunch campaign attributed to Storm-2945, a sub-cluster of the Russia-linked Midnight Blizzard group, was seen using “manipulated network traffic and captive portals” in attacks on 29 September.
In a blog post update, Microsoft Threat Intelligence (MTI) added that the activity was consistent with reports from Lumen research arm Black Lotus Labs and said: “Storm-2945’s continued access to these upstream providers has likely enabled this rapid re-deployment.”
MTI’s initial warning in July said the campaign used domains mimicking Microsoft online services for phishing operations that “abuse the device-code authentication flow in Microsoft Entra ID.”