Microsoft reports that a fake browser update via an intercepted hotel Wi-Fi connection was utilized to distribute the Remote Access Trojan (RAT), which captures webcam footage, audio from microphones, and keystrokes, among other things This article explores revealed microsoft impersonating. . Researchers monitor the operation labeled CaptiveCrunch, attributing it to Storm-2945.

Researchers advise travelers to use private connections and avoid accepting software updates, certificates, browser updates, troubleshooting tools, or security utilities offered through captive portals. Microsoft's assessment indicates that the implant can perform idle-triggered screenshots, capture clipboard contents with active window titles, steal browser cookies and saved passwords, including those protected by Chrome App-Bound Encryption, scan removable media, and establish a remote shell connection.

Researchers discovered ChocoShell, an in-memory PowerShell stealer that collects Microsoft 365 and Azure Active Directory access and refresh tokens, as well as Web Account Manager (WAM) tokens from .tbres files stored in the Token Broker cache. ReliaQuest revealed that the same Microsoft impersonating domains and overlapping infrastructure were documented eight days prior, suggesting a connection to APT28, also known as GRU unit Fancy Bear or Forest Blizzard, but without attribution due to reliance on similar TTPs rather than direct technical evidence. ReliaQuest has low to medium confidence in the possibility that an exposure of management interfaces combined with weak or reused administrator credentials likely granted unauthorized access, but visibility limitations precluded further verification.