Russian Hackers Compromise Hotel WiFi Gateways Globally
A recent hacking wave has compromised hotel WiFi gateways across the globe, and Microsoft has linked the attacks to a Russian state-sponsored group called Storm-2945. The hackers modified DNS traffic on hotel networks to redirect users to Microsoft-themed phishing sites or malware downloads. According to Microsoft, the campaign is far larger and more complex than initially reported, with WiFi gateways compromised at various organizations, not just hotels and conference centers.
The attackers used two new strains of malware, CornFlake RAT and CocoShell, a PowerShell-based infostealer, which communicated with FruitStone, a never-before-seen command-and-control panel. When users were redirected to phishing sites, the attackers sought to steal device codes and OAuth codes for Microsoft Entra accounts, allowing them to bypass MFA and harvest data from target Microsoft accounts and inboxes.
The campaign is linked to Midnight Blizzard, an old Russian hacking group also known as APT29 and Cozy Bear, a renowned cyber unit inside Russia's Foreign Intelligence Service. The attacks started in May and are not connected to another Russian hacking operation called FrostArmada, which involved hacking routers to redirect users to Microsoft-themed phishing pages.