A Russian state-sponsored advanced persistent threat (APT) group is orchestrating a new credential theft operation targeting public Wi-Fi gateways, according to a report by Microsoft. This campaign leverages compromised routers at organizations utilizing captive portal networks to redirect users to attacker-controlled sites.
DNS Manipulation and AitM Techniques
The campaign was initially identified by ReliaQuest about a week ago when they noticed changes in DNS settings on small office/home office (SOHO) routers. These modifications allowed attackers to conduct adversary-in-the-middle (AitM) attacks, intercepting Microsoft 365 credentials from employees across various sectors, including finance, legal, and healthcare.
ReliaQuest observed similarities to a known espionage effort, FrostArmada, linked to APT28, also known as Fancy Bear. However, they stopped short of formally attributing the activity. Microsoft now attributes the campaign to Storm-2945, a subgroup of Midnight Blizzard, believed to be tied to Russia’s Foreign Intelligence Service (SVR).
Operation CaptiveCrunch: Expanding Access
Microsoft has identified the campaign as CaptiveCrunch, noting that Midnight Blizzard often engages in credential compromise and advanced techniques to bypass authentication processes, thus broadening their access within organizations. This subgroup began manipulating DNS and HTTP traffic from captive portal networks in May, likely exploiting shared services in these environments.
The attackers have employed Golang-based remote access trojans (RATs), disguised as browser updates, for reconnaissance and data theft. These RATs enable the collection of credentials, session tokens, files, and even allow for surveillance and remote shell access.
Broader Implications and Future Outlook
Storm-2945 has been deploying various tactics, including ClickFix techniques, to prompt users to download malware. They have targeted both Windows and Android users, using methods that lead victims to install malicious APK files.
Microsoft highlights the widespread compromise of Wi-Fi networks in hospitality sectors and other venues using captive portal equipment. The group has been managing its operations through the FruitStone web-based control panel and continues to evolve its strategies.
Recent CaptiveCrunch pages have directed users to Microsoft sign-in pages, requesting device codes in a bid to authenticate their session, a method consistent with past device code phishing operations by Midnight Blizzard. While not entirely new, the integration of this technique into captive portal attacks may increase user susceptibility to these threats.
As cyber threats continue to evolve, organizations are urged to bolster their network security measures and remain vigilant to protect against such sophisticated attacks.
