Skip to content
Back to Guavy Wire
Stocks

Microsoft Links Hotel Wi-Fi Attacks to Russian Hackers

Instruments
MSFT
Share

Microsoft has linked a global campaign of Wi-Fi attacks targeting hospitality networks to the Russian threat actor Midnight Blizzard (APT29). The campaign, named CaptiveCrunch, manipulates DNS settings on hotel and conference equipment to steal Microsoft 365 accounts.

The company believes this activity is connected to Storm-2945, a sub-cluster of Midnight Blizzard, and has identified two malware families used for persistent access: CornFlake and ChocoShell. These families allow the attackers to steal credentials, surveil devices, and exfiltrate data.

Microsoft analyzed the attack's modus operandi, which involves intercepting user connections through captive portals. This allows them to redirect victims in three ways:

The first method leads to phishing pages impersonating Microsoft 365 login portals. The second uses device code phishing pages that exploit Microsoft Entra ID authentication flows.

The third, newly disclosed, involves fake browser and operating system update pages that deliver malware to Windows through ClickFix prompts requesting user verification.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc