Russia's SVR Hackers Exploit Hotel Wi-Fi Networks for Microsoft 365 Account Takeover
Russian hackers are targeting hotel Wi-Fi networks to compromise Microsoft 365 accounts and install custom malware. The hackers, linked to Russia's Foreign Intelligence Service (SVR), use a tactic called 'adversary-in-the-middle' (AitM) to intercept user connections and redirect them to phishing pages that impersonate Microsoft 365 login portals.
According to Microsoft, the campaign, dubbed CaptiveCrunch, has been active since May 2026 and targets hotels, hospitality establishments, conference centers, and other popular venues in the US, India, and Saudi Arabia. The hackers also use AI to support their efforts, including malware coding and OAuth code phishing.
The malware, known as CornFlake and ChocoShell, can obtain persistent access, harvest credentials, exfiltrate data, and perform audio and video surveillance. Microsoft recommends treating hotel Wi-Fi networks as untrusted and using cellular networks while using corporate devices in public venues.