Олег ОнопрієнкоHot News
4 August 2026, 12:47
2026-08-04
Microsoft cyber experts study: Russian hackers infect Wi-Fi networks in hotels around the world
Microsoft has warned of a new, massive cyber espionage campaign by Russian hackers targeting business travelers. The attackers are hacking into legitimate Wi-Fi networks in hotels and conference centers around the world to steal credentials and deploy malware on the devices of diplomats, government officials and NGO workers through fake updates.
Microsoft has warned of a new, massive cyber espionage campaign by Russian hackers targeting business travelers. The attackers are hacking into legitimate Wi-Fi networks in hotels and conference centers around the world to steal credentials and deploy malware on the devices of diplomats, government officials and NGO workers through fake updates.
Details of the new threat, dubbed CaptiveCrunch, are reported in a report from Microsoft's Threat Intelligence division.
According to researchers, the campaign has been active since at least May 2026 and focuses primarily on users in the US and Europe. It is being carried out by Storm-2945, a unit of the notorious Russian hacking group Midnight Blizzard (also known as APT29, NOBELIUM, or Cozy Bear), which is directly linked to the Russian Foreign Intelligence Service.
Instead of directly attacking secure corporate networks, Russian intelligence agencies have shifted their focus to vulnerable environments where employees are not paying attention. Hackers are compromising so-called captive portals, the login pages through which guests typically connect to free hotel Wi-Fi.
Once connected to a compromised network, attackers manipulate DNS and HTTP traffic, redirecting victims to convincing Microsoft phishing pages or offering to download fake browser or Windows updates. Using the ClickFix tactic, hackers force users to install the CornFlake remote access trojan (RAT) or the ChocoShell info stealer themselves.
This malware allows you to steal Microsoft 365 credentials, files, passwords, and session cookies. In addition, the Trojan is capable of recording keystrokes, capturing screen images, and covertly activating microphones and cameras on the infected device for long-term espionage.
Experts warn that this campaign may be just the beginning, and Wi-Fi networks at airports, universities, and hospitals could be at risk. Microsoft recommends that corporate travelers never install updates via pop-ups when connecting to public networks, use reliable VPNs, and, if possible, use corporate portable routers.