Threat Analysis: APT29 Hotel Wi-Fi Credential Harvesting, AI-Orchestrated PaperCut Attacks, and What UK SMBs Need to Know

Threats & Attacks

Threat Analysis: APT29 Hotel Wi-Fi Credential Harvesting, AI-Orchestrated PaperCut Attacks, and What UK SMBs Need to Know

This is your Daily Threat Analysis for the 11th of September 2026.

Two campaigns today. Both active. Both carrying direct exposure for UK SMBs. Neither requires you to be a named target.


CaptiveCrunch: APT29 Is Sitting Between Your Staff and the Hotel Wi-Fi Login Page

Zscaler published analysis this week of a campaign they have named CaptiveCrunch. The attribution is to Midnight Blizzard, the actor also known as APT29, also known as Cozy Bear, the Russian state group responsible for the SolarWinds supply chain operation and, before that, the 2016 DNC intrusion. If your mental model of APT29 is “very sophisticated, attacks governments and defence contractors, probably not my problem”, this campaign should update that model.

What the research describes is the manipulation of DNS and HTTP traffic on captive portal networks: hotel Wi-Fi, conference centre networks, hospitality venues. The attack intercepts the moment a user tries to authenticate to the Wi-Fi and redirects them to attacker-controlled infrastructure. From there, the operation collects Microsoft 365 credentials through spoofed login pages, device code phishing that abuses the Microsoft Entra ID authentication flow, and ClickFix-style social engineering to deliver malware.

Device code phishing is worth pausing on, because it is particularly effective against users who have MFA enabled and think they are therefore protected. The attack presents a legitimate-looking device code prompt, the kind Microsoft uses when you authenticate a TV app or a shared device. The user enters the code on what they believe is a Microsoft page. They are not on a Microsoft page. The attacker captures a valid authentication token. MFA has been bypassed without the attacker ever knowing the user’s password.

The advisory attributes this to APT29. What it does not say explicitly is that this technique, abusing captive portal redirect windows to intercept credentials, has been observed in various forms since at least 2022. The specific Entra ID device code abuse vector has been documented in multiple campaigns. What is new here is the scale and the sophistication of the infrastructure being used to execute it at hospitality venues specifically, suggesting deliberate targeting of business travellers.

The SMB relevance is this: you do not need to be a government contractor or a defence supplier for your Microsoft 365 tenancy to be valuable. If an attacker can harvest the credentials of a partner at a law firm, an account manager at a professional services business, or a director at an SME attending an industry conference, they have access to email, SharePoint, Teams, and whatever cloud applications that account connects to. The downstream damage from a compromised M365 account in a small business frequently exceeds the damage in a large enterprise, because the controls to contain it are rarely in place.

What to do right now:

  • If your organisation does not operationally require device code authentication flow in Microsoft Entra ID, disable it. This removes the primary technical vector the campaign exploits.
  • Enforce conditional access policies that flag authentication attempts from unexpected geographic locations or unfamiliar devices.
  • Brief any staff who travel, whether to conferences, client sites, or hotels, on the risk of connecting to venue Wi-Fi without an active VPN. This is not a new message. The NCSC has published guidance on this. The fact we are still having this conversation tells you everything about how seriously organisations take it.
  • Do not rely on MFA alone. Device code phishing is specifically designed to bypass it.

AI-Orchestrated PaperCut Exploitation: Zero to Compromise in Under Four Hours

The second item today comes from two separate research teams, GreyNoise and Blackpoint Cyber, who have both published analysis of an active exploitation campaign targeting PaperCut NG and MF print management software. The vulnerabilities are CVE-2026-81578 and CVE-2026-82078.

PaperCut is not a household name, but it runs in a significant proportion of UK professional services environments. Law firms use it. Accountancy practices use it. Universities use it. Hotels use it. If your office has a managed print service with any complexity to it, there is a reasonable chance PaperCut is somewhere in the chain, possibly managed by your IT provider, possibly running on a server you have not thought about in two years.

Here is the detail that makes this campaign worth your attention beyond the usual “patch this” advisory: GreyNoise’s analysis found evidence that the actor used AI agents, specifically models including DeepSeek and OpenAI’s Codex, to automate the entire attack workflow. Vulnerability research. Proof-of-concept development. Target identification. Campaign execution. The analysis found timestamped state files documenting an iterative process that went from an empty workspace to first remote code execution in under four hours. At least 440 PaperCut installations were compromised globally.

The advisory attributes this to a likely Russian-speaking actor. What that framing does not capture is what this represents operationally: AI-assisted exploitation is no longer a theoretical concern. The time between a vulnerability being identified and weaponised is now measurable in hours, not days. The volume of targets that can be scanned, assessed, and exploited within a single campaign has increased by an order of magnitude. An SMB running unpatched PaperCut is not a low-value target that attackers will pass over because there are bigger fish. They are simply one of 440 entries in an automated target list.

Blackpoint’s parallel analysis, which they have titled rather pointedly as “Death by a Thousand PaperCuts,” confirms the same CVEs and adds detail on the post-exploitation behaviour: credential harvesting and lateral movement through the network once initial access is established.

What to do right now:

  • Check whether PaperCut NG or MF is running in your environment. If you use a managed IT provider, ask them directly, in writing, whether they have patched against CVE-2026-81578 and CVE-2026-82078. Get a date, not an assurance.
  • If PaperCut is internet-facing, it should not be. These vulnerabilities are being exploited via internet-exposed instances.
  • Check for signs of post-exploitation activity: unusual scheduled tasks, new local administrator accounts, outbound connections to unfamiliar destinations from the print server.
  • If you are unsure whether you are affected, treat it as if you are until you have confirmed otherwise.

Also on the Radar Today

A couple of items that did not make the lead but are worth a brief note.

GitLab CVE-2026-85706, BleepingComputer reports that GitLab has issued an urgent advisory for a maximum-severity path traversal vulnerability. If you run a self-hosted GitLab instance, common in software development businesses and agencies, patch immediately. GitLab Cloud customers are already protected. The detail to watch for here is whether this vulnerability appears in subsequent KEV entries; path traversal at maximum severity in a widely-deployed platform is exactly the profile that attracts rapid weaponisation.

The Conti sentencing, A Ukrainian national was sentenced to four years in US federal prison today for his role in Conti ransomware development between 2021 and 2022. He was a trained lawyer who developed malware on the side. The sentence is modest relative to the damage Conti caused, the group extorted hundreds of millions of dollars from victims including the Irish Health Service Executive. Four years is not nothing. It is also not a deterrent. The structural conditions that make ransomware-as-a-service profitable have not changed. The group that became Conti largely reconstituted under other banners. The infrastructure continues to operate. A conviction is worth noting. It is not worth mistaking for a resolution.


The Wider Pattern

Three of today’s significant items, CaptiveCrunch, the PaperCut AI campaign, and the passkey-themed social engineering campaign published by Microsoft on Tuesday, share a structural feature: they are all attacking the authentication layer. Credentials. Session tokens. Device codes. The attackers are not breaking encryption. They are not exploiting obscure kernel vulnerabilities. They are impersonating legitimate authentication flows and collecting what users hand over.

The NCSC published guidance on phishing-resistant MFA and conditional access controls well before any of these campaigns emerged. The controls that would limit the damage from CaptiveCrunch and the passkey campaign are documented, available, and frequently not deployed. That is not a technology problem.


If Threat Analysis is useful to you, follow the show wherever you listen, tomorrow’s briefing will land automatically. And if you know someone who needs the heads-up today, pass it on. These campaigns are active. The window between published research and attempted exploitation is narrower than it has ever been.


Sources

SourceTitleURL
Zscaler ThreatLabzCaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentialshttps://www.zscaler.com/blogs/security-research/captivecrunch-midnight-blizzard-weaponizes-hotel-wi-fi-captive-portals
GreyNoise IntelligenceAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MFhttps://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf
Blackpoint CyberDeath by a Thousand PaperCuts: AI-Driven Exploitation at Scalehttps://blackpointcyber.com/blog/death-by-a-thousand-papercuts-ai-driven-exploitation-at-scale/
Microsoft Security BlogPasskey-themed social engineering leads to identity and cloud compromisehttps://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/
BleepingComputerGitLab urges users to patch max severity path traversal flawhttps://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
BleepingComputerConti ransomware gang member sentenced to 4 years in prisonhttps://www.bleepingcomputer.com/news/security/conti-ransomware-gang-member-sentenced-to-four-years-in-prison/

Filed under

  • nation-state-attacks
  • credential-theft
  • smb-security
  • cloud-security
  • remote-access
  • social-engineering
  • incident-response