```html ``` We Named the Wrong Russians. Six Days Later Microsoft Named the Right Ones. Here Is Why We Do Not Have to Retract It.
top of page

We Named the Wrong Russians. Six Days Later Microsoft Named the Right Ones. Here Is Why We Do Not Have to Retract It.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 4 minutes ago
  • 5 min read

On 25 July we published a post about attackers compromising the captive-portal appliances that run guest Wi-Fi at hotels, poisoning DNS at the gateway, and taking Microsoft 365 accounts from travellers who never received a phishing email. The technique description was right. The indicators were right. We named APT28 — Russian military intelligence, the GRU.


On 31 July, Microsoft published its own analysis of the same campaign and attributed it to Midnight Blizzard, specifically a sub-cluster it tracks as Storm-2945. That is the SVR. Russian foreign intelligence. A different service, a different chain of command, and a different reason to be sitting in a hotel network.


We named the wrong Russians. This post is about why that is survivable, and what it would have cost if we had written it the way most people write it.



What we actually said


The relevant paragraph from 25 July, reproduced in full because the wording is the whole point:



ReliaQuest assesses low-to-medium confidence on tradecraft overlap with APT28, the Russian military intelligence group also tracked as Fancy Bear and Forest Blizzard. They are explicit that this rests on technique overlap and not on shared infrastructure, code reuse, or an operator OPSEC failure. That is a careful attribution and we are going to repeat it as carefully as they made it.


Three things are doing work there. It names whose assessment it is. It states the confidence level — low-to-medium, not "linked to". And it says what the assessment rests on, which was technique overlap and explicitly not infrastructure, code, or an operator mistake.


None of that was hedging for its own sake. Technique overlap is the weakest axis you can attribute on, because techniques are the most copyable thing an operator owns. Infrastructure gets reused, code gets reused, and operators make mistakes — those leave marks that are hard to fake. A technique is just a thing that works, and things that work spread.


So when the attribution moved, the sentence did not break. It still accurately describes what ReliaQuest assessed on 23 July with the evidence available on 23 July. What changed is that a company with a great deal more telemetry looked at the same campaign and reached a different answer.



What Microsoft found




Microsoft named the campaign CaptiveCrunch and put a timeline on it that is longer than the public one was. AI-augmented device-code phishing from February. DNS and HTTP manipulation through captive portals from May. Device-code phishing redirects identified on 16 July, a week before the first public disclosure.


Its basis for tying Storm-2945 to Midnight Blizzard is what ours was not: overlaps with Storm-2372, another Midnight Blizzard sub-cluster, plus device-code and OAuth phishing tracked across 2025, Microsoft Graph-based email exfiltration, and consistent victimology. That is four axes, at least two of which are infrastructure-adjacent rather than technique-adjacent.


The tooling is new to the public picture. CornFlake is a Windows RAT that hides behind fake update windows — Windows Update, Defender scans, DirectX — and does keylogging, clipboard capture, screenshots, audio and video, USB monitoring and remote shell, with browser credential theft that defeats Chrome's App-Bound Encryption. ChocoShell is a PowerShell infostealer that runs in memory, disables AMSI by .NET reflection, carries three separate UAC bypasses, impersonates a SYSTEM token to decrypt Chrome's App-Bound Encryption, and abuses the Chrome DevTools Protocol to pull cookies out in plaintext. The operators ran it all from a web panel called FruitStone, dressed up as a product called "CloudSync Console" with invented corporate branding.


One detail deserves its own sentence. Microsoft observed that ChocoShell was written with full developer comments explaining the operator's intent, and assessed that the consistent coding standard and descriptive commentary suggest the author leveraged AI-assisted code generation — and that Storm-2945 is using AI across a significant portion of these operations. An intelligence service left the comments in. That is not a slip an experienced malware author makes; it is what code looks like when a model wrote it and nobody stripped it.



What this would have cost written the normal way


The standard construction is "Russian state hackers linked to APT28 are hijacking hotel Wi-Fi." It is shorter, it reads with more authority, and on 25 July it would have been indistinguishable from what we published to anyone skimming.


It would also now be wrong in a way that cannot be repaired, because the sentence asserts the thing that moved. The fix is a retraction, and a retraction on attribution is expensive twice — once because the post was wrong, and again because every future attribution you publish gets read against it.


We have written that expensive correction before. On 19 July we corrected a post that claimed a two-month lead over Bitdefender when our own timestamps showed we had ingested their research one day after they published it. That one was a real error with a real fix, and the rule we wrote afterwards — no lead claim ships without a comparator timestamp — exists because of it.


This is the other outcome. Same category of risk, different handling, no retraction needed. The difference is entirely in whether the sentence asserts or attributes.



The operational part


If you run travel-heavy staff, none of the attribution matters to you. The technique held across all three publications and that is the part that touches your network.


Six addresses and four domains are in our free feed right now, confidence 90 for the set ReliaQuest published and 75 for the three Microsoft added, and every one of them clears the threshold to appear in the blockable IP list. No registration, no key, no invoice. Block them tonight.


The device-code angle is the piece worth briefing people on, because it survives everything else. The user opens a browser on hotel Wi-Fi, is shown a short code, enters it at a genuine Microsoft URL, and authenticates for real against real Microsoft with real MFA. The session lands with the attacker because the attacker is the device that requested it. Nothing was bypassed. MFA verified that the human was who they claimed to be, which was never the question. Turning off device-code flow for users who do not need it is a tenant setting and it closes this.



What we are taking from it


Three things, and they are all about how the sentence is built rather than about Russia.


Name whose assessment it is. "ReliaQuest assesses" ages gracefully. "Researchers say" does not, and "is linked to" is a claim wearing a disguise.


Publish the confidence level, not just the conclusion. Low-to-medium is information. Dropping it to save eleven words converts somebody's careful hedge into your flat assertion, and you now own it.


Say what the assessment rests on. Technique overlap, infrastructure overlap, code reuse and OPSEC failure are not the same strength of evidence and should never read the same on the page.


We were wrong about which service. We were right about the mechanism, right about the indicators, and right to repeat the hedge exactly as ReliaQuest made it. Two out of three, and the one we missed is the one we did not claim.



Confidence


About 85%. Firm: our own publication dates and wording, ReliaQuest's 23 July disclosure, Microsoft's 31 July attribution and its stated basis, the malware capabilities, and the indicator set — we verified all six addresses and the domains are live in our own feed before writing that they were.


Softer: Microsoft does not publish a numeric confidence for the Storm-2945 to Midnight Blizzard link, so "a different service entirely" reflects its assessment rather than a proven fact. Attribution can move a second time. If it does, this post is built so that it will not need retracting either — and we will write that one too.




How do AI models see YOUR brand?

AIPM has audited 250+ domains. 15 seconds. Free while still in beta.


bottom of page