Russian Hackers Infect Hotel Wi-Fi Networks Globally
Microsoft's Threat Intelligence division has released a report detailing a massive cyber espionage campaign by Russian hackers targeting business travelers. The attackers, part of the notorious hacking group Midnight Blizzard (also known as APT29, NOBELIUM, or Cozy Bear), are compromising captive portals on hotel Wi-Fi networks to steal credentials and deploy malware.
The campaign, dubbed CaptiveCrunch, has been active since at least May 2026 and focuses primarily on users in the US and Europe. The hackers manipulate DNS and HTTP traffic to redirect victims to convincing Microsoft phishing pages or offer fake browser or Windows updates. This allows them to install the CornFlake remote access trojan (RAT) or the ChocoShell info stealer.
Using the ClickFix tactic, hackers force users to install malware themselves, which enables them to steal Microsoft 365 credentials, files, passwords, and session cookies. The Trojan is also capable of recording keystrokes, capturing screen images, and covertly activating microphones and cameras on the infected device for long-term espionage.