Russian Hackers Use Phony Sign-in Pages to Steal Hotel Wi-Fi Login Credentials
Microsoft has issued a warning about a cyber threat targeting hotel Wi-Fi networks. The operation, named 'CativeCrunch,' is attributed to Russian hackers and involves phishing attacks on business travelers.
The hackers use phony sign-in pages to steal login credentials and infect devices with malware. This campaign, linked to the Russian espionage group Storm-2945, has been active since May and affects hospitality networks worldwide.
According to Microsoft, the hackers manipulate network traffic to display fake verification checks and software updates, tricking users into downloading malware called CornFlake and ChocoShell. These malware can steal credentials, record keystrokes, and capture audio and video.