Microsoft Warns Hackers Are Targeting Hotel Wi-Fi Networks: What to Know, How to Protect Yourself
Microsoft said the campaign steals credentials and tokens and can install CornFlake, a remote-access trojan that records keystrokes and screenshots.
- Microsoft warned Windows users Friday that "Organizations should assume that public and hospitality network infrastructure might not be trustworthy," citing the Russian-linked CaptiveCrunch campaign targeting hotel WiFi networks.
- Storm-2945, a sub-cluster of the Russian group Midnight Blizzard, uses AI to enhance CaptiveCrunch's effectiveness against corporate travelers, Microsoft reported. The campaign has targeted hospitality networks worldwide since May.
- Attackers deploy fake sign-in pages and the 'CornFlake' RAT to hijack devices, while 'ClickFix' landings trick Android users into installing malicious APK files. The RAT can record keystrokes, steal credentials, and hijack audio and video capabilities.
- Microsoft recommends travelers use mobile hotspots and strengthen Conditional Access, while thanking "Anthropic and OpenAI for their collaboration and support during this investigation." The company also blocks device-code authentication when unnecessary.
- A July report from ReliaQuest found hackers targeting Microsoft 365 users through compromised WiFi gateways, confirming ongoing risks to public network infrastructure. The findings underscore persistent threats to hotel and venue connectivity.
46 Articles
46 Articles
Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware
Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centersVictims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malwareCornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokensThreat actors are taking over Wi-Fi networks in hotels and conference centers and using the log-in portals …
Microsoft warns Russian hackers are hijacking hotel Wi-Fi to steal user accounts
Microsoft calls the operation the almost cereal-sounding name of CaptiveCrunch. It says the attacks have been active since at least early May and are being carried out by Storm-2945, an operational sub-cluster of Midnight Blizzard. The infamous Midnight Blizzard, also known as Cozy Bear, APT29, and Nobelium, is linked to...Read Entire Article
Microsoft warns travelers amid hospitality-related Wi-Fi hacks
Microsoft is warning travelers to be cautious when connecting to hotel Wi-Fi networks after identifying a campaign in which hackers use fake login pages to steal account credentials. The warning comes as many Granite Staters head out on vacation or welcome visitors staying at hotels across New Hampshire.
Microsoft issues warning on Wi-Fi networks at hotels - WSVN 7News | Miami News, Weather, Sports
(WSVN) - Microsoft has issued a warning on Wi-Fi networks to increase online security.The company said that Russian hackers are now using hotel Wi-Fi networks
Coverage Details
Bias Distribution
- 48% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium



















