Microsoft has linked a global campaign targeting hotel Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The activity was previously disclosed in a report by cybersecurity company ReliaQuest, which detailed how attackers changed DNS settings on Wi-Fi devices in hotels to steal Microsoft 365 accounts. Microsoft attributed the campaign to Storm-2945, a sub-cluster of Midnight Blizzard. Microsoft identified two malware families, CornFlake and ChocoShell, used in the attacks and capable of persistent access, credential theft, surveillance, and data exfiltration. Microsoft named the campaign CaptiveCrunch and said it has been active since at least early May. The same threat actor has been running device and OAuth code phishing operations since February. Somali travelers—whether businesspeople, diaspora members, or tourists—face tangible risks from this kind of attack. Many routinely connect to hotel Wi-Fi in cities across Africa, the Middle East, Europe, and North America. Ensuring Microsoft 365 accounts are protected with multi-factor authentication, and being cautious about entering credentials on login pages accessed through public Wi-Fi, can help guard against sophisticated intrusions. If a login page looks suspicious or if the connection seems off, switching to a mobile data connection before proceeding is the safer move.