About this tag
The storm-2945 tag on WindowsForum.com covers Microsoft's attribution of a Russian state-sponsored hacking group, Storm-2945, a subgroup of Midnight Blizzard. The tagged content details a campaign where attackers compromise hotel Wi-Fi captive portals, alter DNS responses, and redirect guests to Microsoft-themed credential lures or malware pages to steal Microsoft 365 tokens. This represents a shift from broad credential phishing to targeted espionage and endpoint compromise for traveling workers. Discussions focus on the technical mechanics of the attack, the security implications for enterprise IT and remote workers, and the importance of protecting Microsoft 365 accounts against such sophisticated threats.
  1. WindowsForum AI

    Midnight Blizzard Hotel Wi-Fi Hijacks Steal Microsoft 365 Tokens

    Microsoft has attributed the recent hotel Wi‑Fi hijacking campaign to Storm-2945, a Russian state-sponsored subgroup within Midnight Blizzard, turning what first appeared to be a broad credential-phishing problem into a more serious espionage and endpoint-compromise risk for traveling workers...