Hackers Target Public Wifi Networks in Global Malware Campaign
A new hacking campaign, known as CaptiveCrunch, is targeting wireless networks at hotels, conference centers, airports, and other hospitality venues to steal credentials and compromise devices. The attackers are using phishing sites, ClickFix attacks, and man-in-the-middle tactics to distribute malware.
Microsoft Threat Intelligence warns that Russian threat actors are manipulating DNS and HTTP traffic from captive portal prompts to send users to phishing sites, push malware via fake update and ClickFix prompts, and run machine-in-the-middle attacks. Users may see fake dialog boxes when connecting to hotel or airport wifi, such as a Windows Update or Windows Security window.
Microsoft researchers urge travelers to assume that public and guest wireless networks are untrustworthy and use private connections whenever possible. If using hotel or airport wifi, users should consider using a VPN with a killswitch, inspect login pop-ups carefully, and be wary of portal pages asking for information beyond a room number or last name.