CaptiveCrunch Hackers Target Travelers on Hotel Wi-Fi Networks Worldwide
Travelers beware: hackers have been compromising hotel Wi-Fi networks worldwide in a massive cyberattack campaign called CaptiveCrunch. State-sponsored threat actors are hijacking connection sessions to target unsuspecting corporate and personal travelers.
Cybercriminals manipulate the network's DNS and web traffic, redirecting browsers to phishing pages that harvest Microsoft 365 credentials, saved passwords, and single sign-on cookies. They also display bogus pop-up prompts masquerading as Windows updates or antivirus scans, tricking users into downloading remote access trojans and info-stealers.
Security researchers highlight that unpatched Wi-Fi driver vulnerabilities could allow nearby attackers to execute malicious code on computers over shared wireless airspace.
To protect yourself, use your personal phone hotspot or a trusted VPN with an active 'kill switch' before accessing sensitive web applications. Never download files to connect and keep your operating system updated with essential security patches. Avoid direct credential entry into pop-up windows that appear immediately following network authentication.