Russian Hackers Exploit Hotel WiFi Networks to Steal Credentials
Microsoft has issued a warning to Windows PC users about Russian hackers infiltrating their devices on hotel WiFi networks.
The company attributed the campaign, called CaptiveCrunch, to Storm-2945, a sub-cluster of Russia's Midnight Blizzard. This global campaign targets corporate travelers with credential theft and malware delivered through compromised guest networks.
Microsoft has been aware of the campaign since May and has impacted hospitality networks and other guest networks served by captive portals worldwide.
The hackers use AI to support CaptiveCrunch, displaying fake verification checks, sign-in prompts, and software updates on legitimate WiFi gateways. Some users are directed to Microsoft's legitimate device-code authentication process, through which the hacker initiates a sign-in attempt and persuades users to enter a code the hacker gives them.
Microsoft advises travelers not to trust hotel, conference, airport, and other guest networks. The company recommends using mobile hotspots, cellular connections, or other private connectivity, avoiding updates through captive portals, strengthening Conditional Access and phishing-resistant authentication, and blocking device-code authentication when not required.