'CaptiveCrunch' Cyberattack Campaign Targets Hotel Wi-Fi Networks Worldwide
A sophisticated cyberattack campaign, dubbed 'CaptiveCrunch', has been targeting guest Wi-Fi networks at hotels and hospitality venues worldwide since at least May. The hacking group Storm-2945, a sub-cluster of the Russian group Midnight Blizzard (also known as APT29 or Cozy Bear), is behind the attacks.
The hackers compromise the underlying Wi-Fi infrastructure of hospitality venues, redirecting unsuspecting guests through fake portals and malicious pop-ups. Once connected, victims are tricked into downloading malicious files or entering sensitive credentials under the guise of routine security checks.
The attackers use two primary methods: fake browser updates and account takeovers. They may prompt users to update their web browser or run network troubleshooting utilities, mimicking official Google security checks. In other instances, users are redirected to convincing fake login screens, allowing the attackers to gain access to victims' Microsoft 365 accounts.
Once malware is installed on a target device, the hijackers gain broad control. They can capture keystrokes, record audio and video, take screenshots, steal browser cookies and stored passwords, and remotely operate the infected device.