HotInfo Menu
✍️ EDITORIAL PICKS
Russian hackers took over hotel Wi-Fi, Microsoft warns. They slip travelers a fake update and steal their passwords

Russian hackers took over hotel Wi-Fi, Microsoft warns. They slip travelers a fake update and steal their passwords

In late July, Microsoft published an analysis of a campaign it named CaptiveCrunch. According to the analysis, attackers gained access to the login pages of Wi-Fi networks in hotels and other locations where guests connect via a so-called captive portal. The company attributes the attacks to the group Storm-2945, which it describes as an operational branch of the Midnight Blizzard cluster linked to Russia's foreign intelligence service, the SVR. Microsoft has been observing manipulation of the login pages since early May 2026, while the broader operation, supported by artificial intelligence, reportedly dates back to February. Microsoft Threat Intelligence ↗

The trick lies not in the Wi-Fi itself, but in the login page. The attackers altered the DNS settings on the devices that serve the portal and redirected guests through their own infrastructure. Instead of the usual connection confirmation, the person is presented with a fake Microsoft 365 login page, a prompt to sign in via a device code, or a notice about a "required update" to their browser or operating system. In the latter variant, the decisive step is taken by the user themselves, who launches the malicious program with their own hand. BleepingComputer ↗

Two tools are deployed. ChocoShell runs only in memory and collects browser cookies, stored passwords, login tokens for Microsoft 365 and corporate Entra ID, as well as Wi-Fi network credentials. CornFlake is a remote access trojan capable of logging keystrokes and clipboard content, taking screenshots, activating the microphone and camera, and monitoring connected USB devices. Since both tools also steal session tokens, the attacker can hijack an already logged-in session. BleepingComputer ↗

The main targets appear to be business travelers. The Record, citing the security firm ReliaQuest, which first flagged the campaign in July, reports affected hotels and other accommodation facilities in several U.S. cities, India, and Saudi Arabia. According to the outlet, any organization that operates a captive portal is at risk — including airports, coworking spaces, universities, and healthcare facilities. The Record ↗

The risk is not limited to preselected guests, since a compromised portal stands in the path of anyone who connects through it. According to Microsoft, some of the fake pages also offered an installation package for Android, meaning the attack is not confined to laptops. The company's recommendation is straightforward: prefer your own mobile hotspot over a public network, do not download any updates over it, and, where possible, businesses should disable device-code sign-in. The Register ↗

Geographic locations

Location: India
Technology Travel 📍 india 🏢 captivecrunch 🏢 cornflake 🏢 microsoft 365 🏢 microsoft 🏢 midnight blizzard 🏢 reliaquest 🏢 the record
🕒

Live Updates

LIVE