Microsoft is warning travelers to be cautious when using hotel, airport, conference and other public Wi-Fi networks following the discovery of a Russian-linked hacking campaign targeting users worldwide.
The campaign, dubbed CaptiveCrunch, has been attributed to Storm-2945, a group connected to Russia’s Midnight Blizzard. Microsoft says attackers compromise guest Wi-Fi systems and use legitimate-looking captive portals to display fake sign-in pages, verification requests and software updates.
Unlike traditional phishing attacks, victims can be redirected to fraudulent pages simply by connecting to a compromised network. In some cases, attackers trick users into entering codes through Microsoft’s legitimate device authentication system, potentially giving hackers access to accounts without stealing passwords or defeating multi-factor authentication.
The campaign can also install malware disguised as Windows updates. Microsoft identified one remote-access trojan, called CornFlake, that can steal credentials and files, record keystrokes, take screenshots and potentially access a device’s camera and microphone.
Android devices may also be targeted through prompts instructing users to download malicious APK files.
Microsoft says the activity has been underway since early May and has affected guest networks worldwide. The company also said AI tools were used to support parts of the campaign.
Travelers are being urged to consider public and hospitality Wi-Fi untrusted whenever possible. Microsoft recommends using cellular connections or mobile hotspots, avoiding software updates offered through guest-network portals and using stronger, phishing-resistant authentication methods.
[source]