Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments.
Retain Microsoft Defender Experts
Microsoft Defender Experts are available to strengthen your teams with expertise when and where you need it. Learn how to elevate your security with expert-led services.