CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

2026-08-03T08:52:10Z625f550ece02239434b906b1a60c7abe4383a39bebe057d659fbb251f48fb8dd
ACR StealerAI securityCaptiveCrunchClickFixMidnight BlizzardRussian threat actorStorm-2945Teams attacksauthentication token theftbrowser credential theftcompromised sign-in portalscredential thefthospitality sectormalware deliveryphishingsocial engineeringsupply-chain security

What happened

Microsoft Security Blog RSS content reports that Storm-2945, a sub-cluster of the Russian Midnight Blizzard threat actor, has compromised hospitality organization sign-in portals since May 2026 in the CaptiveCrunch operation to deliver malware to travelers and steal credentials. The feed also highlights ACR Stealer campaigns using ClickFix lures to obtain browser credentials, authentication tokens, and sensitive documents, alongside broader phishing, Teams social-engineering, AI-security, and supply-chain security topics.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
625f550ece02239434b906b1a60c7abe4383a39bebe057d659fbb251f48fb8dd
Enrichment time
2026-08-03T08:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft · Baitaphish