CaptiveCrunch: Hackers Hijacking Public Wi-Fi Networks to Steal Login Credentials
A malicious hacking group called Storm-2945 is behind the widespread CaptiveCrunch attack campaign, which has been targeting public Wi-Fi networks in hotels and airports. The attackers use manipulated DNS queries to redirect users to phishing sites that mimic Microsoft's official online services.
These fake sites are designed to intercept login credentials for Microsoft accounts. The hackers can then use these credentials to take over the affected accounts. Additionally, the malware installed on victims' devices allows the attackers to spy on device activity, record keystrokes, and steal sensitive files and passwords.
Microsoft is warning users against the use of public Wi-Fi networks, especially when traveling. The company believes that compromised captive portals may be a key factor in how the attackers gain access to these networks. A good VPN can help protect devices from being hacked through public Wi-Fi networks.