Microsoft Warns of Russian-Made Malware Compromising Public Wi-Fi Users
Microsoft has discovered a sophisticated malware campaign called CaptiveCrunch that targets users of public Wi-Fi, particularly travelers and other vulnerable individuals. The attacks are being run by the Russian hacking group Storm-2945, which is a sub-cluster of the larger Midnight Blizzard group.
CaptiveCrunch compromises users through falsified prompts at the captive sign-in screen, including phishing pages that steal logins or fake Windows or Android system update/download prompts. Once installed, the malware enables keylogging, credential theft, audio/video surveillance, USB drive monitoring, and remote command execution to PowerShell or Command Prompt.
Microsoft's investigation into how these networks are initially compromised is ongoing, but patterns suggest the attackers have access to shared services within the captive portal ecosystem. To protect against CaptiveCrunch, Microsoft recommends users minimize trust in guest networks, use private connectivity, educate organization members on phishing prompts, and employ multi-factor authentication.