Russian Hackers Exploit Hotel Wi-Fi Networks for Government Credential Theft
Russian hackers have been using rogue hotel Wi-Fi networks to steal account credentials from government officials and defense personnel, according to Microsoft's threat intelligence team.
The group, known as Midnight Blizzard or Cozy Bear, sets up fake 'Evil Twin' networks that mimic legitimate hotel connections. When a target connects, the attackers intercept traffic and use NTLM relay attacks to capture Windows authentication hashes, allowing them access to accounts without needing actual passwords.
This campaign has been ongoing since at least 2018, with targets including NATO member government officials, defense contractors, and those with access to sensitive foreign policy information. The hackers have also chained compromised devices, such as home routers and IoT hardware, to route attacks through, making it harder to trace the traffic.
Microsoft advises travelers to use a VPN on public Wi-Fi, verify network names with hotel staff before connecting, or use a trusted mobile hotspot for sensitive activities. The group's infrastructure is linked to Russia's SVR foreign intelligence service, and its targets align with Russian intelligence priorities.