INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
| 2026-08-01 14:11 CRITICAL HIGH DATA BREACH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
On August 1, 2026, Russian hackers hijacked hotel Wi-Fi to steal Microsoft 365 tokens. The attackers are believed to be behind the incident, according to sources. Approximately 345,000 individuals had their medical and financial data exposed due to a CareCloud breach that occurred around the same time as this attack. The hackers exploit vulnerabilities in hotel Wi-Fi networks to intercept sensitive information from users who access Microsoft services while connected to these networks. As of now, no further updates on the incident have been reported.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
pi•••@se•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
2f•••••.com
se•••••.com
se•••••.affairs
re•••••.com
fc•••••.html
wh•••••.html
CI•••••.jpeg
si•••••.html
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign ClassicCampaign Classic
APT29APT29
SednitSednitSofacySofacy
Target & Sectors
JP
energyenergy
healthhealth
hospitalityhospitality
manufacturingmanufacturing
Incident Timeline
May 2026
Russian hackers hijacked hotel Wi-Fi networks to redirect guests into Microsoft's legitimate device code authentication flow, potentially stealing Microsoft 365 tokens.
Click on any entity below to view its context and source!
infrastructure
Microsoft 365
_“ChocoShell collects Microsoft 365 and Azure Active Directory (AD) access tokens, refresh tokens, and Web Account Manager (WAM) tokens from.tbres files in the Token Broker cache.
infrastructure
Windows
The malware delivered through these networks is CornFlake, a full-featured Windows remote access trojan written in Go.
_
ChocoShell also implements three silent UAC bypass techniques with ordered fallback, disables Windows Defender signature updates, and uses Chrome DevTools Protocol to extract browser cookies by launching the browser with a remote debugging port.
infrastructure
Android
Microsoft also found indications that Storm-2945 may be targeting Android devices through the same landing pages, which include instructions to download and install an APK.
2026/08/01
Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers.
Click on any entity below to view its context and source!
infrastructure
Microsoft 365
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens.
Hacking
* Intelligence
* Malware
* Security
* Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
## Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
_!
Image 7
## Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers.
threat_actor
APT29
Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear.
infrastructure
Windows
CornFlake is delivered via ClickFix-style pages that impersonate Windows Update screens, Google verification pages, DirectX installers, browser update prompts, and disk optimization utilities — whatever looks most plausible for the venue.
_“CornFlake registers as a Windows service named svchost32 with the display name “Cloud Sync Service**”**and description “Synchronizes files with the cloud storage provider”, deliberately mimicking the legitimate svchost.exe process.” continues the…
“It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks, and a persistence watchdog routine that runs continuously to restore any persistence mechanism that is removed by defenders o…
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens.
Hacking
* Intelligence
* Malware
* Security
* Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
## Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
_!
Image 7
## Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers.
_“ChocoShell collects Microsoft 365 and Azure Active Directory (AD) access tokens, refresh tokens, and Web Account Manager (WAM) tokens from.tbres files in the Token Broker cache.
Metrics
infrastructure
Windows
Affected Product
CornFlake is delivered via ClickFix-style pages that impersonate Windows Update screens, Google verification pages, DirectX installers, browser update prompts, and disk optimization utilities — whatever looks most plausible for the venue.
The malware delivered through these networks is CornFlake, a full-featured Windows remote access trojan written in Go.
_“CornFlake registers as a Windows service named svchost32 with the display name “Cloud Sync Service**”**and description “Synchronizes files with the cloud storage provider”, deliberately mimicking the legitimate svchost.exe process.” continues the…
“It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks, and a persistence watchdog routine that runs continuously to restore any persistence mechanism that is removed by defenders o…
_
ChocoShell also implements three silent UAC bypass techniques with ordered fallback, disables Windows Defender signature updates, and uses Chrome DevTools Protocol to extract browser cookies by launching the browser with a remote debugging port.
Metrics
infrastructure
Android
Affected Product
Microsoft also found indications that Storm-2945 may be targeting Android devices through the same landing pages, which include instructions to download and install an APK.
Intelligence Sources
Security Affairs
2026-08-01
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
31x
organisation
Identified Entity
Adobe
entity
11x
attribution
Attributing Entity
SilverFox
authority
7x
timeline
Temporal Reference
July 16
date
4x
tactic
Cyber Operation Type
Impersonation
tactic
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
source region
Origin Country
Russian Federation
country
3x
infrastructure
Affected Product
Microsoft 365
software
2x
malware
Malware Payload
Sofacy
tool
Contextual Telemetry
Context Block
7 METRICS
general metric
Microsoft
365
microsoft
campaign
Campaign
Campaign Classic
operation
target region
Target Country
Japan
country
threat actor
APT Group
APT29
actor
industry
Targeted Sector
Hospitality
sector
general metric
Cyber
345,000
cyber
general metric
Bugs
1,072
bugs
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.