CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

2026-08-01T14:52:10Z39dac4f1fdb604307a6d6324206cb351a2eade594ce427925951ee6d4326025d
ACR StealerAI red teamingAI securityCaptiveCrunchClickFixMicrosoft Security BlogMidnight BlizzardRussian threat actorStorm-2945Teams social engineeringauthentication token theftbrowser credential theftcredential thefthospitality sectorleast privilegemalware deliveryphishingsupply chain security

What happened

Microsoft Security Blog RSS collection covering July 2026 security news, including the CaptiveCrunch campaign attributed to Storm-2945/Midnight Blizzard, hotel portal compromises used for malware delivery and credential theft, ACR Stealer ClickFix campaigns targeting browser credentials and tokens, phishing trends, AI security, and defensive initiatives.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
39dac4f1fdb604307a6d6324206cb351a2eade594ce427925951ee6d4326025d
Enrichment time
2026-08-01T14:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.