Microsoft Warns of Widespread Phishing Campaign Targeting Hotel and Airport Wi-Fi
Microsoft has raised alarm over a widespread attack campaign called CaptiveCrunch, in which Russian hackers are using manipulated DNS queries to redirect users to phishing sites that mimic Microsoft's official online services.
The attackers aim to intercept and steal login credentials for Microsoft accounts, capturing device and OAuth codes in the process. They also install malware on victims' devices, including Trojans that record keystrokes, eavesdrop on device activity, and spy via hijacked cameras.
Microsoft believes the hacker group Storm-2945 is responsible for this wave of CaptiveCrunch attacks, which are made possible by compromised public Wi-Fi networks like those found in hotels and airports.