Russian Hackers Hijack Hotel Wi-Fi for Microsoft Account Heists
Microsoft has uncovered a Russian state-backed campaign targeting hotel and conference Wi-Fi networks to steal Microsoft 365 accounts. The operation, dubbed CaptiveCrunch, has been active since at least early May and is linked to Russia's Foreign Intelligence Service.
The attackers compromise hospitality networks using captive portals, manipulate DNS and HTTP traffic, and redirect users through infrastructure they control. Victims are sent to convincing login pages or fake browser prompts designed to install malware.
Some victims see a Microsoft 365 login page with an attacker-supplied code, while others receive fake browser or Windows Update prompts. The attackers use custom tools, including CornFlake and ChocoShell, which can record keystrokes, monitor the clipboard, and capture screenshots.