Russian State Hackers Target Hotel Wi-Fi Networks Worldwide
Russian state-sponsored hackers have launched a global cyber espionage campaign targeting public Wi-Fi networks at hotels and conference centers to breach the devices of corporate executives and government travelers, Microsoft Threat Intelligence reported on August 5.
The campaign, dubbed CaptiveCrunch, is being conducted by a group tracked as Storm-2945, which Microsoft assesses to be an operational unit of Midnight Blizzard, the Russian state threat actor previously linked by US and UK intelligence to Russia's Foreign Intelligence Service (SVR).
By compromising the management systems behind hotel Wi-Fi registration pages, the Russian intelligence unit manipulates internet traffic and redirects guests to malicious infrastructure disguised as legitimate browser updates or system prompts.