CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
2026-08-03T08:52:10Z•625f550ece02239434b906b1a60c7abe4383a39bebe057d659fbb251f48fb8dd
ACR StealerAI securityCaptiveCrunchClickFixMidnight BlizzardRussian threat actorStorm-2945Teams attacksauthentication token theftbrowser credential theftcompromised sign-in portalscredential thefthospitality sectormalware deliveryphishingsocial engineeringsupply-chain security
What happened
Microsoft Security Blog RSS content reports that Storm-2945, a sub-cluster of the Russian Midnight Blizzard threat actor, has compromised hospitality organization sign-in portals since May 2026 in the CaptiveCrunch operation to deliver malware to travelers and steal credentials. The feed also highlights ACR Stealer campaigns using ClickFix lures to obtain browser credentials, authentication tokens, and sensitive documents, alongside broader phishing, Teams social-engineering, AI-security, and supply-chain security topics.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 625f550ece02239434b906b1a60c7abe4383a39bebe057d659fbb251f48fb8dd
- Enrichment time
- 2026-08-03T08:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.