Russia's CaptiveCrunch Campaign Hijacks Hotel Wi-Fi Worldwide Using AI
Russian state-sponsored hackers have been targeting public Wi-Fi networks at hotels and conference centers worldwide, using artificial intelligence (AI) to power their operation. According to Microsoft Threat Intelligence, the campaign, named CaptiveCrunch, has been operating since early May with the goal of stealing login credentials from corporate and government business travelers.
The hackers exploit equipment and management systems behind hotel Wi-Fi registration pages, known as captive portals, to manipulate domain name system (DNS) and hypertext transfer protocol (HTTP) traffic. This redirects guests through infrastructure under their control, allowing the hackers to deliver malware, including a Windows remote access trojan called CornFlake.
Midnight Blizzard, an operational sub-cluster of Storm-2945, is reportedly responsible for the attack. The group has been linked to Russia's Foreign Intelligence Service (SVR) and has a long history of targeting Western institutions. Microsoft noted that Midnight Blizzard's objectives rarely change, with a focus on collecting intelligence through longstanding and dedicated espionage in support of Russian foreign policy interests.
The CaptiveCrunch campaign shares similarities with a separate DNS hijacking operation reported in April. The investigation into how the captive portal networks were initially breached is ongoing, but shared equipment and management systems across multiple affected venues suggest the intrusions may stem from a common point of access.