Microsoft Warns of Russian Hackers on Hotel WiFi Networks
Microsoft has issued a warning to Windows PC users about Russian hackers infiltrating their devices on hotel WiFi networks. The tech company attributed the campaign, called CaptiveCrunch, to Storm-2945, a sub-cluster of Russia's Midnight Blizzard.
CaptiveCrunch targets corporate travelers with credential theft and malware delivered through compromised guest networks. According to Microsoft, the hackers use AI to support their attacks, which can deliver malware directly to users' devices disguised as Windows updates.
The tech company has identified a remote-access trojan (RAT) called CornFlake, designed to record keystrokes, collect files, and steal credentials. CornFlake can also hijack a device's audio and video capabilities for surveillance and give hackers persistent access.