Russian Hackers Hijack Hotel Wi-Fi Networks with Fake Sign-in Pages
Microsoft has issued a security warning regarding a new cyber threat targeting hotel Wi-Fi networks. The operation, named 'CativeCrunch,' involves hackers using phony sign-in pages to steal login credentials and infect devices with malware.
This campaign, linked to the Russian espionage group Storm-2945, has been active since May and affects hospitality networks worldwide. Hackers tamper with Wi-Fi equipment at hotels and conference centers, redirecting users to fake Microsoft 365 login pages.
According to Fox News, compromised network can appear normal, making the attack difficult to detect. The cybersecurity firm ReliaQuest reported compromised Wi-Fi gateways in several U.S. cities, targeting various industries, including financial services and healthcare.
Microsoft's warning highlights the use of AI by Storm-2945 to support the campaign. Hackers manipulate network traffic to display fake verification checks and software updates, tricking users into downloading malware.
The malware, named CornFlake and ChocoShell, can steal credentials, record keystrokes, and capture audio and video.