Russian Hackers Target Hotel WiFi Users with AI-Powered Attacks
Microsoft has issued a warning to Windows PC users about Russian hackers infiltrating their devices on hotel WiFi networks. The company attributed this campaign, known as CaptiveCrunch, to Storm-2945, a sub-cluster of Russia's Midnight Blizzard.
CaptiveCrunch targets corporate travelers with credential theft and malware delivered through compromised guest networks. Microsoft discovered the campaign in May, but its impact has been global, affecting hospitality networks and other guest networks served by captive portals worldwide.
The hackers use AI to support their attacks, displaying fake verification checks, sign-in prompts, and software updates on users' devices. In some cases, they even direct users to Microsoft's legitimate device-code authentication process, which can issue valid authentication tokens without requiring a password or multi-factor authentication.
Microsoft has also identified a Windows remote-access trojan (RAT) called CornFlake, designed to record keystrokes, collect files, steal credentials and session tokens, and capture screenshots. The RAT can even hijack a device's audio and video capabilities for surveillance.