SYMBOLCOMMON_NAMEaka. SYNONYMS

Storm-2945  (Back to overview)


Storm-2945 is a sub-cluster of Midnight Blizzard conducting targeted traffic manipulation attacks on hospitality sector networks served by captive portals, leveraging doppelganger domains for AitM phishing and malware delivery. Their operations include AI-augmented device code and OAuth code phishing campaigns leading to Entra device registration and data collection from Microsoft 365. The primary malware used is CornFlake, a Windows RAT that features customizable capabilities for data collection and evasion. Storm-2945 also utilizes the FruitStone web-based C2 panel to manage their campaign infrastructure and compromised endpoints.


Associated Families

There are currently no families associated with this actor.


References
2026-07-31Microsoft Threat Intelligence
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
ChocoShell CornFlake Storm-2945

Credits: MISP Project