CaptiveCrunch campaign
CaptiveCrunch is an ongoing espionage campaign reported on by Microsoft on July 31, 2026. According to the report, CaptiveCrunch is carried out by a Midnight Blizzard’s sub-group currently tracked as Storm-2945. Midnight Blizzard is a long-established state-sponsored group commonly attributed to Russia’s Foreign Intelligence Service (SVR). The group has been active since 2008 and has been tracked under various names, the most widely adopted are APT29, Cozy Bear, The Dukes, or NOBELIUM.
The CaptiveCrunch campaign has been operating since May 2026. Although Midnight Blizzard is known for targeting government and diplomatic agencies, NGOs, and IT providers, CaptiveCrunch’s campaign seems to focus on corporate travelers capitalizing on captive portals. A captive portal is the web page that appears when the user connects to a public Wi-Fi network (such as at a hotel, airport, etc) prompting the user to accept terms, enter email address, or provide room number before allowing the user to browse the internet. In this campaign Storm-2945 are redirecting the traffic to an attacker-controlled site for follow-up compromise making captive portals the perfect delivery mechanism.
The attack chain works as follows:
- Initial compromise: the victim is redirected through the compromised captive portal and manipulated into downloading malware or otherwise completing device code phishing, rendering access to the attacker.
- CornFlake RAT: if the malware is downloaded, CornFlake is installed establishing a persistence backdoor with a C2 encrypted communication channel and broad remote access capabilities.
- ChocoShell PowerShell stealer: with CornFlake installed, it can then be used to activate ChocoShell, which harvests credentials, browser cookies, Microsoft 365 tokens, and Wi-Fi credentials.
- FruitStone C2 portal: attacker-controlled dashboard to manage infected hosts, issue tasks, configure malware, deploy new payloads, and review stolen data.
One key observation from the Microsoft report is the operational reach of Storm-2945 facilitated by AI tooling. With malware campaigns being boosted, enhanced, and leveraged with AI, defenders must continue challenging the status quo– removing a single file does not reflect containment or remediation.
Variant Discovery in Action
Stairwell’s Recursive Variant Discovery clusters files sharing the same underlying intent, behavior, similar code infrastructure, import-table, among other characteristics. This workflow allows for a broader, more comprehensive, coverage that goes far beyond a singular payload file. Adding a recursive component ensures the threat and any files sharing the same capabilities are eliminated to the fullest extent. Starting from the two file IOCs published by Microsoft, Variant Discovery identified 70 related variants. To read more in depth about Stairwell’s Variant Discovery, check our latest Hidden Malware report showcasing an expanded detection scale.
We used the two file IOCs from Microsoft’s original report as seeds for Variant Discovery, yielding the following results from our petabyte malware corpus:
Variant Discovery’s Findings
CornFlake RAT EXE - 66 variants - SHA256: 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593
760b8c2a13db8fffc3595b55d6c6d134e14d98c0959c3b99c723e2ef27bfff1e 14fe5ade2fa09a2fc5c4a033dac1ab7a91e6ebbefc495c310770dddd96781aeb 9a333f4765b69248333302e87aada6f6f0d549a5c67e850465613c87126b4a76 a4b1c3386e62dd51957461a9360956d6af4a39f837f9f145b5bb19a450858889 b05951fb514dae46137d623e8e877f400320ddc8ddee1417ffc27db0cb1f3dc4 0d75cc9a81c7de62fa4d8f45f5fc625fec0de2b26911c28a5d13d9c626f6f1b7 3dde67f4c0f48810b7efaf24323671861cf693237e696624d3ecb4fac321b185 5395b5c00f0adccd58c1d25eb1b1ec308327b40c7b9a2d1b4dabca54022f9067 f94384ee403f62c989ef258eca3af6643abbac1e71120ed93638a50b41e0726c 5c95842ae185093b3a04d76cd91abed472b02c957670047758dd9b9228b8878d 85d78e636d0f07ff91a419dfc3159b354d95f56f15f1b54ff8ed0a09a752d9c9 c3d601673c2fd3d3e116c17ea35a6c3cd722b12c1a532b41a9e56e0f57688a91 6a862c887136bea0e30e1d0d1cd98c11c6f92393ba47fa34506596bf3c8e3208 e1e2fe6c62640a6af5f7e5b5ef177d1b199b7ca573d299c5e9bfc61fd688c203 ecd3d08e2a5a7a94fe631be1138cd1b0aaa74ce1d68ea4b296078fcacb6dbdd6 fdb4d1ed15aa18ca964889c5402f71e77392ea17f70f15f2bc40631b9be138e9 26f43320f02a9afb64115260d77e91dcc80e6368e2713edefb4964dd4446fa2e 2808468102409a9d98e89ec0bef717013a9a01e54f1b18c954232a3b15516a5b 881c35ac584c4d890616f79a37494078255ab5c4cfb85a02cf5706767693974d 23188e5faf026da26bf55ecff9dde809776ae0f5247993b76ba36d1a5b234982 8898e6baa7f12fd48daf091c89fb4b704c77e2ed588c767ff2772895d784efc9 910ebd402bb64d322be7d09d6e9793992914bac469e5a9edae1bdcf97c25487d a1c754595696302411899d4686daa9a8b18b6251ed5683be59e34a20e9029e39 1b469e99624759644b2f1d3e566769d840ab4351384a4589be2b552dab624cc1 449ef90a303df3e01f23b5bc57232bfa7b2d0275a83dff4a43a49ba7022abe6c edb1f5c3f2801446bd0004fa9978342c084a594857062e9aad65902da2cef2f9 3d92f161f138b631feeb8b759744c974d5b2ee64148010fab16c60aa1f369692 4485ba7e38b4692c7af585b98e65b8abf4977d3b57947b60e5b272e0e035ad9e 509e7ed5e6e5fcaf981f67ececb5c61ed1cb77144825ae9f5a4a6b45d7358903 ea3f8bcf90f8f9c7ff65d9dfe55885ee18bc40c5acb158771b895cce840a582b 13dd9df6eada79f8b27bd8188c8d09072bbc4e0932cfbbf9ae53b7f69266b570 855b141d4f0744787b145917fcfbd1af3c08ec6717d5d4e46d237989ec948c1e 3b8386cb12c8b27404108128d29b77bdd09ffbb73084ab2f4baf67945c0777c7 4f2f15b09eb5e2a66a46769147c65cf142dc428233492335103523dbd151d71f 5e1ab350f019b2944e96a27b675fc0d4ec9ea8a8ff07d69ea8d6eed630e64098 85f76f3475f9a6f2fc1fb1fadbd6925e71b0c43d7a97e5afce8c250fdcae4cf0 bab4d009eae885810a1d7ea885051fec432eb9509c585142e11b1ff5c306a128 faefe788a4067e27166a01fd418b009dfbf95c1574590fdd73453a633e0ebd33 f32c1866d054baa6bce00c0de6e3682eaca007725f86882dfd904e4fa28e6f6e 248e67f1a3b6528517c03b262f0626c2148c7cb26a6869155b469405043aa300 b6fd14189e777383da7db4793c44568a9d516774f5d9bc11d63843db30dcac85 b743668a60f325f027ead058c3797f343629874210e7dc4521ce73236f7a3efd e643cc66c2a5295f47f6e03b5f2effbe28493ad61855019cc6728e1a68ea9a22 ed231c57519240913318749a29bbc490acb3611dd958c0363dc3cd40e4bc3ec7 f1dfe9b4f1e2753fadb6aca32605b68c68cf5734d8e7c76cc5c4a7f407d4019d f449328f531204bff1fa251a330436731fc1f4d1b3b87dfadb2c4ca5d8ac04a2 0c9ecb0039eb7e99f28ac27106f197f483746912e5cfd49a68a8be70931975c4 49f166bbf60ef4de09eafca6ba6477cd038466b8be2a7b5a9a998669edce25d2 7d07900ae98f5b8998fc774266d9e73929704f4350909405acae91eb44847265 0871b47561dab277a9f5e0a55d27a27ac8523fd125ec7b8f53ee29aa90cab759 8200313380511cef47eff1e8f79faec137f07030db31db66d62a47b4b218dad1 f916008ed0bf7731d5b42f8ef131f88f414dee5c404a0c9679b766209c6eefe9 3be54f06ff7730500bdf9655446541aed1fdb4d259158b42cb27551fead9b316 9291f666147e20959994d1b2ea56b9f13d2f0d6f0f35aa2f9658b9c749c03c86 a492f606848b22ba6df4ecf2834e18f889d40f553457c3a93a3b2571b6edbab7 6d77b866a0147eebd3cbb80819df541b91b86ec285f14a05eb803feaab59377b 4bb9b078b5577e5df121ef2c8e2ae5a2e5aa5609fa6dae2cd5c2876b9ee31169 5a7d83215751fec9ae2ea8ced10bf4ff6779c4e8915f20b3fb38ad6d2eef439a c76da6639845045916dc08c8c6c3af5771352d204881257a807700582356b464 2948eea6648fc387f19b72f509fabf3c01a5fda77f726d21df460623c2a5ebc1 be431a47b81faed551798305a4ae6dd851a8be4abfbf0235a272a47e3f09bc08 d15e350af680a36535a12e16dca09e55c74c219e3a7ee14abdbb87e0dd107770 d9deae35fad94e1bbba9325ab3e2f7e4b47369b5836a46e4fd4caaaa4ea38a5a c648d1f6d9e2e0c00b4cdfdd04b35a1948b2204e86cddd766395bc27b5f71124 4d4a83b4a75a0fea9dbc589a08e9a5fdcd699ec3dcbfd3d0160e4d71a4e03b6f bf0c79320209002aad644ceb1ec169bc078ffde3077c9cb184cede4286dfe0e1
ChocoShell PowerShell - 4 variants - SHA256: Be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
1e3ee845fde739fcd3ca9ce62c7f142a7c501d11db4c4fb294d4939f12d0f916 403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f 6f7090895c1c3dee30de6b3f098ca3a788dc198646e5293a8b1210430b0add97 28f622028e690c943f7fa9aca426c07cab52b5aaba757ef8a3328609c0b3bec3