Russian SVR operatives (Storm-2945/Midnight Blizzard) are compromising public Wi-Fi captive portal networks at hotels and conference centres to deliver sophisticated malware, in a campaign Microsoft calls "CaptiveCrunch." By manipulating DNS and HTTP traffic to position themselves as adversary-in-the-middle, attackers use ClickFix-style fake prompts — disguised as OS updates or driver repairs — to trick users into installing malware, including a full-featured Windows RAT called CornFlake and an in-memory credential-stealing tool called ChocoShell. The campaign also incorporates device code phishing to hijack victims' Microsoft 365 accounts, with Microsoft advising users to avoid public Wi-Fi where possible and organisations to disable device code authentication flows to limit exposure.