Russian hackers took over hotel Wi-Fi, Microsoft warns. They slip travelers a fake update and steal their passwords
In late July, Microsoft published an analysis of a campaign it named CaptiveCrunch. According to the analysis, attackers gained access to the login pages of Wi-Fi networks in hotels and other locations where guests connect via a so-called captive portal. The company attributes the attacks to the group Storm-2945, which it describes as an operational branch of the Midnight Blizzard cluster linked to Russia's foreign intelligence service, the SVR. Microsoft has been observing manipulation of the login pages since early May 2026, while the broader operation, supported by artificial intelligence, reportedly dates back to February. Microsoft Threat Intelligence ↗
The trick lies not in the Wi-Fi itself, but in the login page. The attackers altered the DNS settings on the devices that serve the portal and redirected guests through their own infrastructure. Instead of the usual connection confirmation, the person is presented with a fake Microsoft 365 login page, a prompt to sign in via a device code, or a notice about a "required update" to their browser or operating system. In the latter variant, the decisive step is taken by the user themselves, who launches the malicious program with their own hand. BleepingComputer ↗
Two tools are deployed. ChocoShell runs only in memory and collects browser cookies, stored passwords, login tokens for Microsoft 365 and corporate Entra ID, as well as Wi-Fi network credentials. CornFlake is a remote access trojan capable of logging keystrokes and clipboard content, taking screenshots, activating the microphone and camera, and monitoring connected USB devices. Since both tools also steal session tokens, the attacker can hijack an already logged-in session. BleepingComputer ↗
The main targets appear to be business travelers. The Record, citing the security firm ReliaQuest, which first flagged the campaign in July, reports affected hotels and other accommodation facilities in several U.S. cities, India, and Saudi Arabia. According to the outlet, any organization that operates a captive portal is at risk — including airports, coworking spaces, universities, and healthcare facilities. The Record ↗
The risk is not limited to preselected guests, since a compromised portal stands in the path of anyone who connects through it. According to Microsoft, some of the fake pages also offered an installation package for Android, meaning the attack is not confined to laptops. The company's recommendation is straightforward: prefer your own mobile hotspot over a public network, do not download any updates over it, and, where possible, businesses should disable device-code sign-in. The Register ↗
The trick lies not in the Wi-Fi itself, but in the login page. The attackers altered the DNS settings on the devices that serve the portal and redirected guests through their own infrastructure. Instead of the usual connection confirmation, the person is presented with a fake Microsoft 365 login page, a prompt to sign in via a device code, or a notice about a "required update" to their browser or operating system. In the latter variant, the decisive step is taken by the user themselves, who launches the malicious program with their own hand. BleepingComputer ↗
Two tools are deployed. ChocoShell runs only in memory and collects browser cookies, stored passwords, login tokens for Microsoft 365 and corporate Entra ID, as well as Wi-Fi network credentials. CornFlake is a remote access trojan capable of logging keystrokes and clipboard content, taking screenshots, activating the microphone and camera, and monitoring connected USB devices. Since both tools also steal session tokens, the attacker can hijack an already logged-in session. BleepingComputer ↗
The main targets appear to be business travelers. The Record, citing the security firm ReliaQuest, which first flagged the campaign in July, reports affected hotels and other accommodation facilities in several U.S. cities, India, and Saudi Arabia. According to the outlet, any organization that operates a captive portal is at risk — including airports, coworking spaces, universities, and healthcare facilities. The Record ↗
The risk is not limited to preselected guests, since a compromised portal stands in the path of anyone who connects through it. According to Microsoft, some of the fake pages also offered an installation package for Android, meaning the attack is not confined to laptops. The company's recommendation is straightforward: prefer your own mobile hotspot over a public network, do not download any updates over it, and, where possible, businesses should disable device-code sign-in. The Register ↗
🔥 You might also like
Iran–Israel
Investigation launched into incident aboard Flydubai flight from Dubai to Tel Aviv
The Attorney General of the United Arab Emirates ordered an investigation into a serious incident aboard a Flydubai aircraft flying from Dubai...
Artificial Intelligence
Bill Gates Warns of a Billion Victims Without Regulation of Artificial Intelligence
Bill Gates warned that without adequate regulation, artificial intelligence could cause the deaths of up to one billion people in the coming months.
Czechia
What Czechia is writing about: The budget has the second-largest deficit ever — Fico continues to face criticism over his remarks about NATO
The government approved a budget with the second-largest deficit in history and is bringing back fuel price regulation. Fico faces criticism over NATO, while ju …
Geographic locations
From our newsroom original
All →
Kaliňák and Krúpa disagree on how Slovakia's security is best ensured

US wants talks with Ukraine and Russia at the end of October

Australia investigates the second pilot of Flydubai flight to Israel

Serbia wants Russian gas even as an EU candidate. The deal expires Wednesday, Vučić hopes for an extension

Albania is pursuing the former intelligence chief. She returned to house arrest, and messages to a fugitive businessman leaked from the case file

Moldova has declared a state of emergency in energy and hydrology. The Chișinău heating plant is seeking an 83 percent increase in heat prices, while Energocom reported an evening deficit

What Europe Is Writing About: Delegates Walked Out of Netanyahu's Speech, Vučić Announced the Time of His Resignation, Trump Hosted Xi Jinping

René Benko's Two-and-a-Half-Year Sentence for Fraudulent Bankruptcy Is Final. Neither Prosecution nor Defense Appealed