CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
2026-08-02T20:52:11Z•0f6faa253f8889692f0ef31914becf762106d1aa525f7937d59d9de85f49d445
ACR StealerAI securityCaptiveCrunchClickFixMidnight BlizzardStorm-2945Teams social engineeringauthentication token theftbrowser credential theftcredential theftdocument thefthospitality sectormalware deliveryphishingthreat intelligence
What happened
Microsoft Security Blog RSS feed containing July 2026 security content. The most significant reported threat is CaptiveCrunch, an operation by Storm-2945, a Midnight Blizzard sub-cluster, compromising hospitality organizations’ sign-in portals to deliver malware to travelers and steal credentials. The feed also covers ACR Stealer campaigns using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents, along with broader phishing, Teams social engineering, AI security, and least-privilege guidance.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 0f6faa253f8889692f0ef31914becf762106d1aa525f7937d59d9de85f49d445
- Enrichment time
- 2026-08-02T20:52:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.