Russian Hackers Target Hospitality Wi-Fi Networks with Custom Malware
A global campaign targeting hospitality Wi-Fi networks has been linked to Russian threat actor Midnight Blizzard, also known as APT29. The attackers use custom malware to breach Microsoft 365 accounts and have been active since at least early May.
The attackers manipulate DNS and HTTP traffic on networks served by captive portal equipment, allowing them to intercept user connections to hotel and conference center Wi-Fi networks.
They redirect victims to phishing pages that impersonate Microsoft 365 login portals or device code phishing pages that abuse Microsoft Entra ID authentication flows. The threat actor also uses fake browser and operating system update pages to deliver malware to Windows via ClickFix prompts for user verification.
The attackers have been using two new Windows malware families, CornFlake and ChocoShell. CornFlake is a Go-based remote access trojan (RAT) that offers various capabilities, including keylogging, clipboard monitoring, and file exfiltration. ChocoShell is an in-memory PowerShell credential stealer that targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.
Microsoft recommends treating hotel and conference Wi-Fi as untrusted, using private cellular or managed connections whenever possible, and avoiding software updates or tools offered through captive portals.