Russian Hackers Target Hotel Wi-Fi Users with Sophisticated Malware Campaign
Microsoft has discovered a sophisticated malware campaign targeting public Wi-Fi users, including travelers and vulnerable individuals who connect to hotel networks. The Russian hacking group Storm-2945, a sub-cluster of Midnight Blizzard, is behind the attacks, which use falsified prompts at captive sign-in screens to compromise user credentials.
The malware, called CaptiveCrunch, can steal logins, install keyloggers, and even monitor USB drives. Victims may also be subjected to machine-in-the-middle (MitM) attacks that route their traffic through an attacker's proxy network, allowing for further credential theft.
According to Microsoft, the attackers have access to shared services within the captive portal ecosystem, suggesting a high level of sophistication and coordination. To protect against CaptiveCrunch, Microsoft recommends minimizing trust in guest networks, using private connectivity methods, educating users on phishing prompts, and employing multi-factor authentication (MFA).
Microsoft has also released a list of specific Microsoft Defender detections and Indicators of Compromise (IoCs) to help identify and mitigate the attacks.