Russian Hackers Use AI to Steal Login Credentials via Hotel Wi-Fi
Russian state-sponsored hackers have been hijacking public Wi-Fi networks at hotels and conference centers worldwide, using artificial intelligence (AI) to power much of the operation.
The campaign, named CaptiveCrunch, has been operating since early May and targets corporate and government business travelers with the goal of stealing login credentials.
Microsoft Threat Intelligence reported that the group, tracked as Storm-2945, is an operational sub-cluster of Midnight Blizzard, a threat actor linked to Russia’s Foreign Intelligence Service (SVR).
The hackers exploited equipment and management systems behind hotel Wi-Fi registration pages, known as captive portals, to manipulate the domain name system (DNS) and hypertext transfer protocol (HTTP) traffic.