Russian Hackers Hijack Hotel Wi-Fi to Steal Passwords
Microsoft has issued a warning about a suspected Russian hacking group that has been hijacking Wi-Fi networks at hotels and conference centers in multiple US cities and abroad. The company confirmed that compromised Wi-Fi gateways are redirecting users to malicious websites, mimicking Microsoft online services, to steal login details.
The hacked Wi-Fi systems also deliver malware via a trap called ClickFix, which tricks users into executing malicious instructions by presenting itself as a legitimate CAPTCHA page or update process. The malware can collect passwords, steal files, and let hackers secretly hijack and monitor their PCs.
Microsoft identified one of the malware attacks as 'Cornflake', which poses as a Windows update, virus scan, document viewer installer, or browser update to infect users' devices. Additionally, Android devices are vulnerable via APK files delivered through ClickFix-style screens.