Russian Hackers Use Hotel WiFi to Infiltrate Devices with AI-Powered Malware
Microsoft has issued a warning to Windows PC users about Russian hackers infiltrating their devices on hotel WiFi networks. The tech company attributed the campaign, called CaptiveCrunch, to Storm-2945, a sub-cluster of Russia's Midnight Blizzard.
CaptiveCrunch targets corporate travelers with credential theft and malware delivered through compromised guest networks. According to Microsoft, the hackers use AI to support their attacks, which can deliver malware directly to users' devices disguised as Windows updates.
The tech company has identified a Windows remote-access trojan (RAT) called CornFlake, designed to record keystrokes, collect files, steal credentials and session tokens, and capture screenshots. CornFlake can also hijack a device's audio and video capabilities for surveillance, giving hackers persistent access.
Microsoft recommends that travelers not trust hotel, conference, airport, and other guest networks, instead using mobile hotspots or cellular connections to stay safe online. The company advises avoiding updates through captive portals, strengthening Conditional Access and phishing-resistant authentication, and blocking device-code authentication when not required.