Russian Hackers Hijack Hotel Wi-Fi to Steal Passwords and Spread Malware
Microsoft has issued a warning about a suspected Russian hacking group that's been using hotel Wi-Fi networks to steal passwords and spread malware. The company confirmed that compromised Wi-Fi gateways are sending users to fake websites that mimic Microsoft online services, tricking them into entering their login details.
The hijacked Wi-Fi systems have also been delivering malware via a trap called ClickFix, which disguises itself as browser or OS updates. One of the malware attacks has been dubbed 'Cornflake' and can pose as a Windows update, virus scan, document viewer installer, or browser update.
ReliaQuest suspected that the hacks involved APT 28 or Fancy Bear, but Microsoft links them to APT 29 or Cozy Bear, another Russian cyberespionage outfit linked to the Kremlin. The company advises users to minimize trust in hospitality and guest networks and rely on their own cellular data instead.