Russian Hackers Target Hotel Wi-Fi Networks in Widespread Attack
Microsoft has issued a warning about a new threat targeting hospitality venues in 'widespread but targeted' internet traffic manipulation attacks. The tech giant attributed the operation, nicknamed 'CaptiveCrunch,' to Russian state-sponsored hackers Storm-2945, a subgroup of Midnight Blizzard.
The attack involves hacking hotel Wi-Fi networks with guest logins or captive portals, prompting users to download malicious files that infect their devices with malware. This allows the hijackers to capture keystrokes, screenshots, audio, and video, as well as monitor the clipboard and operate the device remotely.
According to Microsoft, users may see a variety of fake windows designed to throw off the user from detecting the scam, including false Windows Update screens, virus scans, and browser update prompts. The company urges users to exercise caution when using guest networks at hotels, conferences, airports, or other public venues, and to rely on private connectivity whenever possible.