NG Solution Team
Cybersecurity

Hotel WiFi Hijacked by Russian Hackers, Microsoft Warns

Microsoft’s threat intelligence team says a Russian-linked group has been hijacking hotel WiFi networks and other shared venues since early May, quietly redirecting guests’ internet traffic through attacker-controlled servers to steal credentials or deliver malware without travellers noticing.

“To date, Microsoft has identified widespread compromise of WiFi networks at hospitality-related organisations and other networks serviced by captive portal equipment in several countries,” Microsoft said in a recent report. The company identified the campaign as CaptiveCrunch, run by a group known as Storm-2945, part of the larger Russian state-sponsored operation Midnight Blizzard, also called APT29 or Cozy Bear. Microsoft declined to disclose the total number of users or organisations affected and referred inquiries to its blog post on the matter.

ReliaQuest has identified this activity not only at hotels, but also conference centres and other shared venues, and assesses that “the goal of this activity is to access the accounts of corporate travellers.” Such venues congregate high-value targets from government, critical infrastructure, defence, health care, finance and technology, meaning a single compromised wireless network can expose hundreds or thousands of potential victims at once.

Hotel WiFi and captive portals targeted

Attackers exploit captive-portal equipment and familiar guest login flows to make malicious activity blend into normal behaviour. Louis Eichenbaum, federal chief technology officer at ColorTokens, said: “Business travellers are conditioned to expect unfamiliar login pages, certificate warnings, and network prompts when connecting to public WiFi. That creates an environment where malicious activity blends into normal behaviour.”

Some CaptiveCrunch landing pages go further by imitating Microsoft’s device sign-in process, the short-code method used to log into devices such as smart TVs. In those cases, the attacker initiates a login on their end and prompts the victim to enter a code on Microsoft’s real sign-in page. While the victim believes they are logging into their own account, they have actually approved the attacker’s session — a session that has already cleared multifactor authentication because the victim just completed that step.

How the scheme hijacks logins

Matt Radolec, field chief technology officer at Varonis, explained the technical risk: “The technique works well because hidden code runs on the user’s device and extracts active login tokens stored temporarily in memory.” Those tokens, intended to keep users logged in for convenience, can be reused by attackers without triggering additional identity checks, making a compromised device easier to exploit.

Radolec also noted that hotel and conference WiFi often receives little security oversight: “They are public networks meant for guests to browse and do whatever they want. These networks are often not secured or monitored at all.”

The shift in attacker tactics away from traditional phishing and toward compromising authentication flows reflects changes in defensive posture, Eichenbaum said: “As organisations improve email security and MFA adoption, adversaries are increasingly targeting the authentication process itself.”

Who is at risk and how to protect yourself

Because the campaign targets venues that gather corporate travellers, employees from high-value sectors are particularly exposed if they use compromised networks. Microsoft and security firms identified hotels, conference centres and other shared venues among the affected locations.

Radolec recommends precautions for travellers: connect through an always-on VPN, think twice before clicking links, and keep computer software updated. He added, “Never assume public WiFi is safe, or that the websites accessed through it can be trusted.”

Related posts

Is Anthropic’s Claude Code a security risk due to a backdoor?

Michael Johnson

Check Point zero-day exploited in production — are patches released?

Michael Johnson

Is there a ‘security backdoor’ in Anthropic’s AI coding tool?

David Jones

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy