Microsoft Threat Intelligence has reported an active campaign it calls CaptiveCrunch, associated with a sub-cluster of Midnight Blizzard. The campaign has manipulated DNS and HTTP traffic on networks served by captive portals, including travel and hospitality environments, to redirect users toward attacker-controlled infrastructure.
Why this matters
Travellers often expect airport, hotel and venue Wi-Fi to redirect them to a sign-in page. That normal behaviour can make a malicious redirect harder to spot. Microsoft says the campaign has also used lookalike Microsoft domains and adversary-in-the-middle phishing techniques, including abuse of Microsoft Entra device-code authentication.
Recommended response
- Prefer a trusted mobile hotspot or known network for sensitive sign-ins when travelling.
- Be cautious if a public Wi-Fi portal suddenly asks you to authenticate to Microsoft 365.
- Use phishing-resistant MFA where practical, such as passkeys or FIDO2 security keys.
- Review unexpected Entra device registrations and revoke suspicious sessions promptly.
- Keep endpoint protection and browsers up to date.
If you think a staff member has entered credentials into a suspicious page, change the password, revoke active sessions and have the account reviewed as soon as possible.