Hotel Wi-Fi Hacking Campaign Targets Corporate Travelers
Microsoft has issued a warning to travelers about a cyberattack campaign targeting hotel and hospitality Wi-Fi networks. The attacks, dubbed 'CaptiveCrunch,' involve compromising public Wi-Fi infrastructure and captive portals used by guests.
The campaign, attributed to Storm-2945, a group linked to the Russian threat actor Midnight Blizzard, has been observed across multiple countries and targets corporate travelers in particular.
Attackers first compromise the network infrastructure or equipment responsible for captive portals. They then manipulate the pages displayed to users, tricking them into installing malware or entering their credentials on fake login pages.