The Russian state-affiliated threat actor Midnight Blizzard (also tracked as Storm-2945 and APT29) is conducting a multi-pronged espionage campaign targeting organizations in the United States and Europe. The group is exploiting CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA), to gain persistent access to victim mailboxes. Concurrently, in a campaign dubbed 'CaptiveCrunch,' the same actor is compromising hotel and conference center Wi-Fi captive portals to intercept traffic, deploy malware, and steal Microsoft 365 and Azure AD authentication tokens from high-value targets. This dual approach demonstrates the actor's sophistication in leveraging both software vulnerabilities and physical-world infrastructure to achieve its objectives.
Actor: Midnight Blizzard is a well-known Russian intelligence-linked group focused on long-term espionage and data theft.
Targets: The campaigns are aimed at a wide range of sectors, including government, telecommunications, financial services, hospitality, and aerospace.
Objectives: The primary goal is to gain and maintain persistent access to sensitive information within victim environments, particularly email communications and cloud-based data.
Midnight Blizzard is employing two distinct but related attack chains:
CornFlake and ChocoShell, are used. These are likely backdoors or info-stealers designed to harvest credentials and session tokens.This activity maps to the following MITRE ATT&CK techniques:
T1059.007 - JavaScript/JScript: Used in the exploitation of the OWA XSS vulnerability.T1557 - Man-in-the-Middle: The core technique of the 'CaptiveCrunch' campaign.T1189 - Drive-by Compromise: How malware is delivered via the compromised captive portals.T1539 - Steal Web Session Cookie: The objective of harvesting M365/Azure AD tokens.Successful exploitation grants Midnight Blizzard significant access to sensitive organizational data. The theft of authentication tokens is particularly damaging as it allows attackers to impersonate legitimate users and bypass MFA, making detection difficult. This access can be used for long-term intelligence gathering, exfiltration of intellectual property, and gaining a foothold for broader network intrusions.
No specific Indicators of Compromise (IOCs) were provided in the source articles.
Security teams may want to hunt for the following patterns:
CornFlake, ChocoShell (if specific process names become known)CornFlake and ChocoShell malware families.Applying the patch for CVE-2026-42897 is the most direct mitigation for the OWA attack vector.
Educating users about the risks of public Wi-Fi can help prevent compromises via the 'CaptiveCrunch' technique.
While token theft can bypass MFA, strong MFA implementations combined with conditional access policies increase resilience.
For the 'CaptiveCrunch' scenario, using a corporate VPN on public Wi-Fi effectively segments the user's device from the local hostile network.
Microsoft indicates that exploitation of CVE-2026-42897 began as early as May 2026.
A broader campaign leveraging the OWA vulnerability was observed to have begun.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.