Russian State Hackers Exploit Hotel Wi-Fi Networks Globally
Russian state-sponsored hackers have launched a global cyber espionage campaign targeting public Wi-Fi networks at hotels and conference centers, Microsoft Threat Intelligence reported on August 5. The campaign, dubbed CaptiveCrunch, is being conducted by a group tracked as Storm-2945, which Microsoft assesses to be an operational unit of Midnight Blizzard, the Russian state threat actor previously linked by US and UK intelligence to Russia’s Foreign Intelligence Service (SVR).
By compromising the management systems behind hotel Wi-Fi registration pages, the Russian intelligence unit manipulates internet traffic and redirects guests to malicious infrastructure disguised as legitimate browser updates or system prompts. This allows them to intercept login tokens and gain unauthorized access to corporate Microsoft 365 environments.
Midnight Blizzard has a documented history of conducting high-priority intelligence collection to support Kremlin foreign policy goals, targeting government agencies, diplomatic missions, and IT service providers across the United States and Europe. By incorporating hotel Wi-Fi traffic manipulation into their arsenal, Russian operatives can bypass conventional perimeter defenses by striking executives while they are away from corporate headquarters.
To counter the threat, Microsoft advised organizations to restrict employee reliance on unverified public Wi-Fi networks, utilize enterprise-managed mobile hotspots or travel routers, and enforce strict identity controls to prevent unauthorized access to corporate cloud resources. The wave of hotel Wi-Fi attacks coincides with an expanding effort by Russian intelligence to breach Western critical infrastructure.