CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
2026-08-01T14:52:10Z•39dac4f1fdb604307a6d6324206cb351a2eade594ce427925951ee6d4326025d
ACR StealerAI red teamingAI securityCaptiveCrunchClickFixMicrosoft Security BlogMidnight BlizzardRussian threat actorStorm-2945Teams social engineeringauthentication token theftbrowser credential theftcredential thefthospitality sectorleast privilegemalware deliveryphishingsupply chain security
What happened
Microsoft Security Blog RSS collection covering July 2026 security news, including the CaptiveCrunch campaign attributed to Storm-2945/Midnight Blizzard, hotel portal compromises used for malware delivery and credential theft, ACR Stealer ClickFix campaigns targeting browser credentials and tokens, phishing trends, AI security, and defensive initiatives.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 39dac4f1fdb604307a6d6324206cb351a2eade594ce427925951ee6d4326025d
- Enrichment time
- 2026-08-01T14:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.