Russian Hackers Target Travelers Through Compromised Public WiFi Networks
Russian state-linked hackers have breached public WiFi networks at hotels, airports, conference centers, and casinos, according to a warning from Microsoft. The campaign, dubbed “Captive Crunch,” targets travelers by redirecting them to fake login pages designed to steal credentials or install malware. Researchers have linked the operation to multiple managed service providers (MSPs) that serve seven of the top 10 US hotel chains, suggesting widespread exposure.
The attackers, identified as part of the Midnight Blizzard group, have been active since at least June 2023. They manipulate network traffic to display spoofed authentication portals, using AI-augmented techniques to enhance their attacks. The hackers have renewed their infrastructure with new domains and IP addresses, ensuring continuous access to compromised networks. Microsoft notes that the rapid redeployment of attacks indicates ongoing access to upstream providers.
The campaign has escalated since February, with waves of attacks linked to different MSPs. Researchers identified over 70 victim IP addresses associated with the campaign, particularly around major cybersecurity conferences in Las Vegas. The malware deployed includes remote access trojans capable of spying, credential theft, and media monitoring. Attackers have used deceptive techniques like fake software updates to trick users into downloading malware.
Microsoft advises travelers to avoid public WiFi networks and instead use mobile hotspots, cellular data, or VPNs. The company recommends treating all public WiFi as untrustworthy and avoiding any unexpected web prompts. Enterprise-managed travel routers or hotspot devices with encrypted tunnels are suggested for added security.