CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

2026-08-01T08:52:10Zb2e3527b0699c066791b29e97a52748649eba7535f5a502422074738015bcbce
ACR StealerAI securityCaptiveCrunchClickFixMicrosoft Security BlogMidnight BlizzardStorm-2945Teams social engineeringauthentication token theftbrowser credential theftcredential theftmalware deliveryphishingthreat intelligence

What happened

Microsoft Security Blog RSS content covering July 2026 security news, including the CaptiveCrunch campaign attributed to Storm-2945/Midnight Blizzard targeting hospitality sign-in portals to deliver malware and steal credentials, ACR Stealer campaigns using ClickFix lures, phishing and Teams-based social engineering trends, and AI security guidance. The document is primarily a news feed; the most directly actionable items describe active credential theft and malware delivery campaigns.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
b2e3527b0699c066791b29e97a52748649eba7535f5a502422074738015bcbce
Enrichment time
2026-08-01T08:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.