CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

2026-08-02T14:52:11Zd575819f4ead395722dc15f334a702820653b2507f111b18d1cebe8ed27baf86
ACR-StealerAI-securityCaptiveCrunchClickFixMidnight-BlizzardRussian-threat-actorStorm-2945authentication-tokensbrowser-credentialscredential-thefthospitality-sectormalware-deliveryphishingsocial-engineeringthreat-intelligence

What happened

Microsoft Security Blog RSS entries covering the CaptiveCrunch campaign attributed to Storm-2945, a Midnight Blizzard sub-cluster, which compromised hospitality sign-in portals to deliver malware and steal credentials; ACR Stealer ClickFix campaigns targeting browser credentials, authentication tokens, and documents; broader phishing and Teams social-engineering trends; and AI security initiatives. The most actionable reports describe active credential theft and malware delivery campaigns observed in 2026.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
d575819f4ead395722dc15f334a702820653b2507f111b18d1cebe8ed27baf86
Enrichment time
2026-08-02T14:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.