Microsoft Warns of Hackers Targeting Hotel Wi-Fi Networks
Microsoft has issued a warning to travelers about using free hotel Wi-Fi networks. The company's Threat Intelligence team has identified a hacking campaign called CaptiveCrunch, which targets hospitality organizations and guest Wi-Fi networks worldwide.
The hackers are believed to be linked to the Russia-linked group Storm-2945, also known as APT29 or Cozy Bear. They have been manipulating DNS and HTTP traffic on captive portals, redirecting users to fake websites that appear legitimate but are actually controlled by the attackers.
Once connected to these fake sites, travelers may see pop-ups asking them to install updates or fix problems. However, these updates can actually help hackers control users' devices and steal their sensitive data.
The malware used in this campaign includes CornFlake, which can steal files, passwords, and login details, as well as take screenshots and record audio and video from infected devices. Another type of malware, ChocoShell, can steal browser cookies, saved passwords, Microsoft 365 login details, and Wi-Fi passwords.
Microsoft advises travelers to treat hotel and guest Wi-Fi networks as untrusted and use mobile hotspots or private connections instead. They should also avoid downloading software updates or security tools from public Wi-Fi portals.