Microsoft Warns of Renewed Cyberattacks on Hospitality Wi-Fi Networks
Microsoft has detected renewed cyberattacks targeting the hospitality industry, leveraging compromised network login pages and exploiting Microsoft Entra ID. The campaign, dubbed CaptiveCrunch, has resurfaced two months after its initial discovery, with fresh activity observed on September 29. The hacking group Storm-2945, a subgroup of the Russia-linked Midnight Blizzard collective, is behind these attacks.
In an updated blog post, Microsoft Threat Intelligence (MTI) noted that the recent activity aligns with findings from Lumen’s Black Lotus Labs. The attackers have been using manipulated network traffic and captive portals to carry out their operations. Microsoft suggests that Storm-2945’s sustained access to upstream providers has facilitated the rapid redeployment of these attacks.
MTI’s initial warning in July revealed that the campaign involved phishing operations using domains that imitated Microsoft online services. These attacks exploited the device-code authentication flow in Microsoft Entra ID, a critical vulnerability that allowed the hackers to bypass standard security measures.