Russian Hackers Exploit Hotel Wi-Fi Networks with Sophisticated Malware Campaign
Microsoft has issued a warning about a sophisticated cyber threat targeting hotel Wi-Fi networks worldwide. The operation, dubbed 'CaptiveCrunch,' is linked to the Russian espionage group Storm-2945 and involves hackers tampering with hotel equipment to redirect users to fake Microsoft 365 login pages.
The compromised network can appear normal, making it difficult for business travelers to detect the attack. According to ReliaQuest, several U.S. cities have reported compromised Wi-Fi gateways targeting various industries, including financial services and healthcare.
The hackers use AI to manipulate network traffic, displaying fake verification checks and software updates that trick users into downloading malware. The malware, known as CornFlake and ChocoShell, can steal credentials, record keystrokes, and capture audio and video.
Microsoft advises travelers to treat public Wi-Fi networks as untrusted and take precautions such as using a mobile hotspot, avoiding updates through captive portals, and employing phishing-resistant authentication. Disabling device-code authentication when not needed can also help prevent unauthorized access.