ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi‑Fi credentials from travelers connecting to compromised hospitality networks worldwide. The operation, dubbed “CaptiveCrunch,” poisons DNS and HTTP flows on guest networks so that travelers attempting to reach legitimate Microsoft 365 or update endpoints are […]
Read the original article:
