Hotels' Public Wi-Fi Hacked by Sophisticated 'CaptiveCrunch' Campaign
A sophisticated hacking campaign called 'CaptiveCrunch' has been targeting hotel Wi-Fi users since February 2026, warns Microsoft's Threat Intelligence Unit. The hackers use doppelganger domains that mimic Microsoft online services to conduct follow-on adversary-in-the-middle (AitM) phishing operations.
Storm-2945, the group behind CaptiveCrunch, has been actively running this campaign for over 18 months. They exploit security vulnerabilities in hotels' public Wi-Fi portals to hack into potential victims' PCs and steal their passwords and even record video and audio during their stay in the room.
The hackers use advanced generative AI to execute this sophisticated attack. Once they take control of the hotel's Wi-Fi, they redirect users through actor-controlled phishing infrastructure and manage to deliver malware.