CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

2026-08-02T20:52:11Z0f6faa253f8889692f0ef31914becf762106d1aa525f7937d59d9de85f49d445
ACR StealerAI securityCaptiveCrunchClickFixMidnight BlizzardStorm-2945Teams social engineeringauthentication token theftbrowser credential theftcredential theftdocument thefthospitality sectormalware deliveryphishingthreat intelligence

What happened

Microsoft Security Blog RSS feed containing July 2026 security content. The most significant reported threat is CaptiveCrunch, an operation by Storm-2945, a Midnight Blizzard sub-cluster, compromising hospitality organizations’ sign-in portals to deliver malware to travelers and steal credentials. The feed also covers ACR Stealer campaigns using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents, along with broader phishing, Teams social engineering, AI security, and least-privilege guidance.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
0f6faa253f8889692f0ef31914becf762106d1aa525f7937d59d9de85f49d445
Enrichment time
2026-08-02T20:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.