Reposted by Daniel Gordon
MSFT updated their blog on the captive portal shenanigans: www.microsoft.com/en-us/securi...
This stuff has been continuing for a while now, and the tooling is evolving too. No new indicators I see in there (or that we are sharing, so not throwing shade) but be on the look out for this stuff!
microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order ...