Dossier
Midnight Blizzard
Coverage of Midnight Blizzard in the Nexus archive.
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The attacks use custom malware to breach Microsoft 365 accounts.
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update distributed via hijacked hotel Wi-Fi is delivering CornFlake, a remote access trojan (RAT) capable of capturing webcam images, microphone audio, and keystrokes. Microsoft attributes the operation, tracked as CaptiveCrunch, to Storm-2945, which is linked to the Midnight Blizzard group.