Feed / Other
highOtherotherms_security_blog · Jul 31, 2026
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
A Russian threat actor, Midnight Blizzard, is targeting travelers through compromised hospitality sign-in portals to deliver malware and steal credentials in an operation called CaptiveCrunch.
“Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The pos”
View original article →Security
threat_protectioncredential_theftmalware_delivery
Audience
security_engineercompliance_officer
Environment
cloudhybrid
Classification confidence: 95%
Loading correlations…