Midnight Blizzard Hijacks Hotel Wi-Fi Networks with Fake Login Pages
Microsoft researchers have discovered that Russian state-sponsored actors, known as Midnight Blizzard or APT29, are hijacking captive portal equipment in hotels and conference centers to steal credentials and deploy information-stealing malware.
Captive portals manage the login pages users see before accessing public Wi-Fi. When connecting to a hotel network, users are often redirected to a page where they must enter their room number, accept the terms of service, and click 'Connect' - this redirection is handled by the captive portal.
The researchers found that when users try to log in on compromised networks, they may be redirected to fake Microsoft 365 login portals that steal their credentials. They may also be taken to device code phishing pages abusing Microsoft Entra ID authentication flows or display fake browser and OS update pages that trick victims into downloading infostealers.
Two malware variants have been identified: CornFlake, an infostealer capable of stealing files, credentials, and device data, and CocoShell, a credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. APT29 is known for its links to Russia's Foreign Intelligence Service and notable attacks on high-ranking western targets.
Microsoft did not explain exactly how the captive portal equipment is attacked, but warns that threat actors are taking over Wi-Fi networks in hotels and conference centers using this method.