September 3, 2026

CaptiveCrunch Shows Why You Can’t Assume a Trusted Wireless Network Is Secure

Connecting to hotel Wi-Fi has become routine for business travelers. An employee selects the hotel network, completes the captive portal, and continues working. The network looks legitimate, and the login process appears familiar. Yet a recently disclosed cyberespionage campaign demonstrates why those familiar signals cannot establish that the infrastructure behind a wireless connection remains trustworthy.

Microsoft Threat Intelligence identified a campaign it calls CaptiveCrunch, in which attackers compromised networks using captive portals at hotels, conference centers, and other shared venues. Microsoft attributes the campaign to Storm-2945, which it assesses as an operational sub-cluster of Midnight Blizzard. The attackers manipulated DNS and HTTP traffic to redirect users through attacker-controlled infrastructure, presenting fake browser and operating system updates and, in some cases, Microsoft authentication workflows. Microsoft says the campaign has operated since at least early May 2026 across hospitality-related networks in several countries.

The campaign illustrates an important evolution in how attackers can exploit wireless connectivity. Attackers do not always need to crack encryption, steal a Wi-Fi password, or convince a victim to connect to an obviously rogue network. They can target infrastructure that users already trust.

The problem is no longer simply whether an employee connected to the expected Wi-Fi network. Security teams must also consider whether the infrastructure supporting that connection remains trustworthy.

The Wi-Fi Network Can Be Part of the Attack

Traditional discussions about public Wi-Fi security often focus on connecting to the wrong network. Travelers are warned about evil-twin access points, rogue hotspots, and networks that impersonate legitimate hotel, airport, or conference Wi-Fi networks. CaptiveCrunch presents a different problem.

Microsoft reports that the attackers gained an adversary-in-the-middle position, allowing them to manipulate traffic and redirect users to malicious infrastructure. The initial method used to compromise the captive portal networks remains under investigation. ReliaQuest found that compromised hospitality Wi-Fi gateways could control DNS resolution for connected devices. With administrative control of that infrastructure, attackers could manipulate DNS responses and redirect traffic toward attacker-controlled destinations. The user could therefore connect to the expected hotel network and encounter what appeared to be a routine captive portal experience, even as the compromised infrastructure had already become part of the attack path.

The compromised infrastructure allowed the attackers to redirect traffic toward malicious destinations, but redirection alone did not install malware on the endpoint. The malware delivery path still relied on the victim downloading or executing attacker-supplied content, while other attack paths targeted credentials and authentication flows. Encryption protected the wireless link, but it could not protect the user from infrastructure that attackers had already compromised.

From Hotel Wi-Fi to Enterprise Compromise

Once attackers control part of the network path, a routine wireless connection can become the beginning of a much larger cybersecurity incident. In the CaptiveCrunch campaign, attackers manipulated traffic to present victims with fake browser or operating system updates. Some pages used ClickFix techniques that instructed users to execute attacker-supplied commands. Microsoft also observed landing pages that directed users into legitimate Microsoft device code authentication flows, potentially allowing victims to authorize attacker-controlled sessions.

The campaign delivered malware capable of stealing credentials and authentication tokens, conducting surveillance, collecting data, and enabling remote access. The wireless connection itself may last only a few hours, but the resulting compromise can persist much longer. A compromised corporate laptop can return to the enterprise environment, while stolen credentials or authentication tokens may provide the attacker with continued access to corporate cloud resources. Hotel Wi-Fi therefore becomes an enterprise security issue when corporate devices and identities move between external wireless environments and internal systems.

Wireless Security Requires More Than Encryption

Modern Wi-Fi encryption addresses an important part of wireless security, but it cannot verify that every component supporting a wireless connection remains trustworthy. CaptiveCrunch illustrates that distinction. The attackers did not need to defeat modern Wi-Fi encryption. They exploited infrastructure that users expected to trust.

Protecting wireless connectivity, therefore, requires security teams to consider more than the radio link itself. Authentication, endpoint behavior, network infrastructure, and the surrounding environment all contribute to the overall security model.

A Familiar Wireless Network Is Not Necessarily a Trusted Network

Microsoft recommends treating hotel, conference, airport, and other guest wireless networks as untrusted and preferring private connectivity when practical. For corporate travelers, endpoint, identity, and connectivity controls remain important defenses. ReliaQuest specifically recommends always-on, full-tunnel VPN configurations that route DNS through trusted corporate infrastructure rather than the venue gateway.

Those controls address the CaptiveCrunch attack path. The incident also raises a broader question for organizations responsible for their own facilities: how do security teams independently determine what wireless devices and infrastructure are actually present? An expected network name does not establish that the underlying infrastructure is legitimate, uncompromised, or behaving normally. 

Authorized Wi-Fi networks operate within a larger RF environment that can also contain rogue access points, unauthorized hotspots, personal devices, and other wireless systems outside normal management processes. Some can impersonate trusted infrastructure or create communication paths that never traverse the managed enterprise network. Security teams therefore need to distinguish between knowing what wireless infrastructure should be present and observing what is actually operating in the environment. That distinction matters because expected wireless infrastructure is not necessarily trustworthy, and direct RF observation provides organizations with an independent source of visibility into the wireless environment within their own facilities. 

Network Visibility Is Not Wireless Visibility

Enterprise security platforms provide extensive visibility into managed infrastructure. Network security tools analyze traffic traversing networks they monitor. Endpoint platforms observe managed devices. Identity systems monitor authentication and account activity. Not every wireless communication is visible in those managed-system telemetry sources.

A rogue access point can operate inside a facility without becoming part of the managed WLAN. A personal hotspot can create an independent internet connection, while wireless devices can communicate directly without traversing the enterprise network. Traditional security tools continue to protect the environments they were designed to monitor. Direct observation of the RF environment provides a different source of information. Network visibility is not wireless visibility.

How Bastille Adds Independent RF Visibility

Bastille Wireless Airspace Cybersecurity adds continuous RF visibility to existing network, endpoint, identity, and physical security programs. Rather than relying on network infrastructure to report which wireless devices are present, Bastille observes wireless communications directly in the RF environment. The platform discovers, identifies, locates, and monitors wireless devices and communications independently of whether those devices connect to the organization’s managed network.

Bastille continuously and passively monitors the RF spectrum from 100 MHz to 6 GHz, with Wi-Fi coverage extending to 7.125 GHz, providing visibility into wireless communications that conventional network-based security technologies may not see. That independent source of information can help security teams identify unexpected access points, unauthorized wireless infrastructure, previously unidentified wireless devices, and changes in the RF environment that warrant investigation.

Bastille does not replace endpoint protection, identity security, VPNs, secure access controls, or other legacy technologies that address different parts of the attack surface. Bastille adds another source of visibility by allowing security teams to observe the wireless environment directly.

Trust Must Be Verified in the Wireless Environment

CaptiveCrunch is more than a warning about unsafe hotel Wi-Fi. It demonstrates how attackers can exploit infrastructure supporting a trusted wireless connection without defeating the security of the wireless link itself. A network can have the expected identity and appear in the expected location while the infrastructure behind it no longer deserves that trust.

For travelers, endpoint, identity, VPN, and connectivity controls help address that risk. Enterprise facilities present a related challenge: security teams also need to understand what wireless devices and infrastructure are actually operating within their own environments.

Endpoint security provides visibility into the device. Identity security provides visibility into the account. Network security provides visibility into managed infrastructure. Continuous RF monitoring adds visibility into the wireless devices and communications operating around them. Together, those sources of visibility provide a more complete understanding of the modern attack surface.

Frequently Asked Questions

What is the CaptiveCrunch campaign?

CaptiveCrunch is a cyberespionage campaign identified by Microsoft in which attackers compromised networks using captive portals at hotels, conference centers, and other shared venues. The attackers manipulated network traffic to redirect travelers toward fake software updates, malicious content, and authentication workflows designed to support credential theft or unauthorized access.

Does WPA2 or WPA3 protect against attacks like CaptiveCrunch?

WPA2 and WPA3 provide important protections for Wi-Fi communications, but wireless encryption does not establish that the network infrastructure supporting a connection has not been compromised. CaptiveCrunch demonstrates how attackers can target trusted infrastructure rather than breaking Wi-Fi encryption itself.

What is the difference between network visibility and wireless visibility?

Network visibility refers to activity observable through the managed network infrastructure and its telemetry. Wireless visibility comes from directly observing RF communications, including devices and communications that may operate independently of the managed network. The two provide complementary views of the environment.

Close your cybersecurity gaps with AI-driven wireless visibility

See Bastille in action with a live demo from our experts in wireless threat detection.