CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
2026-08-01T08:52:10Z•b2e3527b0699c066791b29e97a52748649eba7535f5a502422074738015bcbce
ACR StealerAI securityCaptiveCrunchClickFixMicrosoft Security BlogMidnight BlizzardStorm-2945Teams social engineeringauthentication token theftbrowser credential theftcredential theftmalware deliveryphishingthreat intelligence
What happened
Microsoft Security Blog RSS content covering July 2026 security news, including the CaptiveCrunch campaign attributed to Storm-2945/Midnight Blizzard targeting hospitality sign-in portals to deliver malware and steal credentials, ACR Stealer campaigns using ClickFix lures, phishing and Teams-based social engineering trends, and AI security guidance. The document is primarily a news feed; the most directly actionable items describe active credential theft and malware delivery campaigns.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- b2e3527b0699c066791b29e97a52748649eba7535f5a502422074738015bcbce
- Enrichment time
- 2026-08-01T08:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.