Microsoft Warns Hackers Are Targeting Hotel Wi-Fi Networks: What to Know, How to Protect Yourself
Microsoft said the campaign steals credentials and tokens and can install CornFlake, a remote-access trojan that records keystrokes and screenshots.
- Microsoft warned Windows users Friday that "Organizations should assume that public and hospitality network infrastructure might not be trustworthy," citing the Russian-linked CaptiveCrunch campaign targeting hotel WiFi networks.
- Storm-2945, a sub-cluster of the Russian group Midnight Blizzard, uses AI to enhance CaptiveCrunch's effectiveness against corporate travelers, Microsoft reported. The campaign has targeted hospitality networks worldwide since May.
- Attackers deploy fake sign-in pages and the 'CornFlake' RAT to hijack devices, while 'ClickFix' landings trick Android users into installing malicious APK files. The RAT can record keystrokes, steal credentials, and hijack audio and video capabilities.
- Microsoft recommends travelers use mobile hotspots and strengthen Conditional Access, while thanking "Anthropic and OpenAI for their collaboration and support during this investigation." The company also blocks device-code authentication when unnecessary.
- A July report from ReliaQuest found hackers targeting Microsoft 365 users through compromised WiFi gateways, confirming ongoing risks to public network infrastructure. The findings underscore persistent threats to hotel and venue connectivity.
59 Articles
59 Articles
The aim of the attacks is to steal records, files and information on hotel users pressing keys.
Microsoft stated that it had identified a massive campaign by Russian hackers against the infrastructure of Wi-Fi public networks in hotels, conference centres and other public places around the world.
Here's Why Microsoft Is Encouraging Users to Stay Off Public Wifi Networks
A new hacking campaign is targeting wireless networks at hotels, conference centers, airports, and other hospitality venues in an attempt to steal credentials and compromise devices.
The Midnight Blizzard hacker group may be behind the spy attacks.
Coverage Details
Bias Distribution
- 41% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium



























