Skip to content
Back to Guavy Wire
Stocks

Russian Hackers Hijack Hotel Wi-Fi for Microsoft Account Heists

Instruments
MSFT
Share

Microsoft has uncovered a Russian state-backed campaign targeting hotel and conference Wi-Fi networks to steal Microsoft 365 accounts. The operation, dubbed CaptiveCrunch, has been active since at least early May and is linked to Russia's Foreign Intelligence Service.

The attackers compromise hospitality networks using captive portals, manipulate DNS and HTTP traffic, and redirect users through infrastructure they control. Victims are sent to convincing login pages or fake browser prompts designed to install malware.

Some victims see a Microsoft 365 login page with an attacker-supplied code, while others receive fake browser or Windows Update prompts. The attackers use custom tools, including CornFlake and ChocoShell, which can record keystrokes, monitor the clipboard, and capture screenshots.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc