Hotel Wi-Fi Networks Compromised by Global Hacking Campaign
Microsoft has issued a warning to businesses about potential security risks when using hotel Wi-Fi networks. The company found that hackers are using compromised guest networks to steal login details through a global hacking campaign called CaptiveCrunch.
The attackers use fake verification pages, sign-in prompts, and software updates that appear to be from legitimate Wi-Fi systems to trick victims into entering their login credentials.
Once approved, the attackers can access accounts using valid login tokens without needing to steal passwords or bypass multi-factor authentication directly. The Windows remote-access trojan, called CornFlake, can also install malware on devices, creating a bigger risk than just stolen login details.