CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
2026-08-02T14:52:11Z•d575819f4ead395722dc15f334a702820653b2507f111b18d1cebe8ed27baf86
ACR-StealerAI-securityCaptiveCrunchClickFixMidnight-BlizzardRussian-threat-actorStorm-2945authentication-tokensbrowser-credentialscredential-thefthospitality-sectormalware-deliveryphishingsocial-engineeringthreat-intelligence
What happened
Microsoft Security Blog RSS entries covering the CaptiveCrunch campaign attributed to Storm-2945, a Midnight Blizzard sub-cluster, which compromised hospitality sign-in portals to deliver malware and steal credentials; ACR Stealer ClickFix campaigns targeting browser credentials, authentication tokens, and documents; broader phishing and Teams social-engineering trends; and AI security initiatives. The most actionable reports describe active credential theft and malware delivery campaigns observed in 2026.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- d575819f4ead395722dc15f334a702820653b2507f111b18d1cebe8ed27baf86
- Enrichment time
- 2026-08-02T14:52:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.