Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian APT Targets Public Wi-Fi in Credential Theft Campaign

Russian APT Targets Public Wi-Fi in Credential Theft Campaign

Posted on August 3, 2026 By CWS

A Russian state-sponsored advanced persistent threat (APT) group is orchestrating a new credential theft operation targeting public Wi-Fi gateways, according to a report by Microsoft. This campaign leverages compromised routers at organizations utilizing captive portal networks to redirect users to attacker-controlled sites.

DNS Manipulation and AitM Techniques

The campaign was initially identified by ReliaQuest about a week ago when they noticed changes in DNS settings on small office/home office (SOHO) routers. These modifications allowed attackers to conduct adversary-in-the-middle (AitM) attacks, intercepting Microsoft 365 credentials from employees across various sectors, including finance, legal, and healthcare.

ReliaQuest observed similarities to a known espionage effort, FrostArmada, linked to APT28, also known as Fancy Bear. However, they stopped short of formally attributing the activity. Microsoft now attributes the campaign to Storm-2945, a subgroup of Midnight Blizzard, believed to be tied to Russia’s Foreign Intelligence Service (SVR).

Operation CaptiveCrunch: Expanding Access

Microsoft has identified the campaign as CaptiveCrunch, noting that Midnight Blizzard often engages in credential compromise and advanced techniques to bypass authentication processes, thus broadening their access within organizations. This subgroup began manipulating DNS and HTTP traffic from captive portal networks in May, likely exploiting shared services in these environments.

The attackers have employed Golang-based remote access trojans (RATs), disguised as browser updates, for reconnaissance and data theft. These RATs enable the collection of credentials, session tokens, files, and even allow for surveillance and remote shell access.

Broader Implications and Future Outlook

Storm-2945 has been deploying various tactics, including ClickFix techniques, to prompt users to download malware. They have targeted both Windows and Android users, using methods that lead victims to install malicious APK files.

Microsoft highlights the widespread compromise of Wi-Fi networks in hospitality sectors and other venues using captive portal equipment. The group has been managing its operations through the FruitStone web-based control panel and continues to evolve its strategies.

Recent CaptiveCrunch pages have directed users to Microsoft sign-in pages, requesting device codes in a bid to authenticate their session, a method consistent with past device code phishing operations by Midnight Blizzard. While not entirely new, the integration of this technique into captive portal attacks may increase user susceptibility to these threats.

As cyber threats continue to evolve, organizations are urged to bolster their network security measures and remain vigilant to protect against such sophisticated attacks.

Security Week News Tags:APT29, CaptiveCrunch, credential theft, cyber espionage, Cybersecurity, Microsoft report, network security, Russian APT, Storm-2945, Wi-Fi security

Post navigation

Previous Post: Thermo Fisher Fixes DNA Software Vulnerability
Next Post: Critical Vulnerability in SonicWall Appliances Exposes Networks

Related Posts

Rokarolla Trojan Threatens Over 200 Banking Apps Rokarolla Trojan Threatens Over 200 Banking Apps Security Week News
Kodak Confirms Data Breach Following Cyberattack Kodak Confirms Data Breach Following Cyberattack Security Week News
Supply Chain Attack Hits SAP NPM Packages Supply Chain Attack Hits SAP NPM Packages Security Week News
Medtronic Confirms Breach Amid ShinyHunters Threat Medtronic Confirms Breach Amid ShinyHunters Threat Security Week News
Red Teaming AI: The Build Vs Buy Debate Red Teaming AI: The Build Vs Buy Debate Security Week News
React Native Aria Packages Backdoored in Supply Chain Attack React Native Aria Packages Backdoored in Supply Chain Attack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • XCSSET v40 Targets macOS Devs via Compromised Xcode
  • Cyberattacks on US Water Systems Linked to Iran
  • Critical Vulnerability in SonicWall Appliances Exposes Networks
  • Russian APT Targets Public Wi-Fi in Credential Theft Campaign
  • Thermo Fisher Fixes DNA Software Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • XCSSET v40 Targets macOS Devs via Compromised Xcode
  • Cyberattacks on US Water Systems Linked to Iran
  • Critical Vulnerability in SonicWall Appliances Exposes Networks
  • Russian APT Targets Public Wi-Fi in Credential Theft Campaign
  • Thermo Fisher Fixes DNA Software Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark