CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

A new cyber threat, dubbed CaptiveCrunch, is exploiting hotel Wi-Fi login pages to steal Microsoft 365 credentials. This sophisticated attack, linked to the group Midnight Blizzard, targets travelers and business users, highlighting emerging risks in public network security.
Key takeaways
- Hotel Wi-Fi login pages are being weaponized for credential theft.
- Microsoft 365 accounts are the primary target of this campaign.
- The attack uses advanced techniques to evade detection.
- Users should exercise extreme caution on public networks.
Why it matters
This campaign demonstrates a novel attack vector targeting remote workers. Users relying on public Wi-Fi for business should be aware that even seemingly legitimate login pages can be compromised, putting sensitive work data at risk.



