Russian Hackers Exploit Hotel WiFi Networks with AI-Powered Malware
Microsoft has issued a warning to Windows PC users about Russian hackers infiltrating their devices on hotel WiFi networks. The tech company attributed the attacks to Storm-2945, a sub-cluster of Russia's Midnight Blizzard.
The campaign, known as CaptiveCrunch, targets corporate travelers with credential theft and malware delivered through compromised guest networks. According to Microsoft, the hackers use AI to support their attacks.
Some users are directed to Microsoft's legitimate device-code authentication process, which can deliver malware directly to users' devices disguised as Windows updates. The company has identified a Windows remote-access trojan (RAT) called CornFlake that allows hackers to record keystrokes, collect files, and steal credentials and session tokens.
Microsoft advises travelers not to trust hotel, conference, airport, and other guest networks. Instead, they recommend using mobile hotspots or cellular connections for private connectivity, avoiding updates through captive portals, and strengthening Conditional Access and phishing-resistant authentication.