Russian Hackers Target Global Public Wi-Fi Networks with Sophisticated Phishing Campaign
Microsoft has revealed a large-scale hacking campaign by Russian hackers targeting public Wi-Fi infrastructure worldwide. The attackers, attributed to Storm-2945 and linked to Russia's Foreign Intelligence Service, exploited captive portals, authorization pages that appear when devices connect to public Wi-Fi networks.
The hackers redirected users to phishing infrastructure under their control and distributed malicious software disguised as browser or operating system updates. These fake update prompts appeared in response to automatic connectivity checks that browsers run after connecting to a new network.
This campaign has been tied to previous high-profile cyberattacks, including the 2020 breach of U.S. government agencies through SolarWinds software and the 2023 breach of Outlook email clients.