Feed / Other
highOtherotherms_security_blog · Jul 31, 2026

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

A Russian threat actor, Midnight Blizzard, is targeting travelers through compromised hospitality sign-in portals to deliver malware and steal credentials in an operation called CaptiveCrunch.

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The pos
View original article →
Security
threat_protectioncredential_theftmalware_delivery
Audience
security_engineercompliance_officer
Environment
cloudhybrid
Classification confidence: 95%
Loading correlations…
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | 365Forge