Microsoft Warns Windows PC Users About Russian Hotel WiFi Hackers
Microsoft has issued a warning to Windows PC users about Russian hackers infiltrating their devices on hotel WiFi networks. The hackers, part of a group known as Storm-2945 and attributed to Russia's Midnight Blizzard, have been targeting corporate travelers with credential theft and malware delivered through compromised guest networks.
The campaign, dubbed CaptiveCrunch, has been impacting hospitality networks and other guest networks served by captive portals worldwide since May. Microsoft discovered the threat after a report from ReliaQuest found that hackers were targeting Microsoft 365 users through compromised WiFi gateways in July.
The hackers use AI to support their attacks, displaying fake verification checks, sign-in prompts, and software updates on legitimate hotel or venue WiFi gateways. Some users are directed to Microsoft's device-code authentication process, which the hackers initiate a sign-in attempt and persuade users to enter a code they give them. If the user approves the request, Microsoft issues valid authentication tokens without needing a password or multi-factor authentication.
The attacks can also deliver malware directly to users' devices disguised as Windows updates. Microsoft has identified a Windows remote-access trojan (RAT) called CornFlake that allows hackers to record keystrokes, collect files, steal credentials and session tokens, capture screenshots, hijack audio and video capabilities for surveillance, and give them persistent access.
Microsoft advises travelers not to trust hotel, conference, airport, and other guest networks, instead using mobile hotspots or cellular connections. The company recommends strengthening Conditional Access and phishing-resistant authentication, avoiding updates through captive portals, and blocking device-code authentication when not required.