Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Hotel Wi-Fi Attacks. Show all posts

Hotel Wi-Fi Attacks Linked to Russian Hackers Target Microsoft 365 Accounts With Custom Malware


In a sophisticated cyber campaign carried out by attackers using hotel and conference Wi-Fi networks, Microsoft uncovered the theft of Microsoft 365 credentials, and the deployment of custom malware. As reported by the company, CaptiveCrunch was carried out by Storm-2945, a subgroup of the Russian state-backed threat actor Midnight Blizzard (APT29). 

There have been several incidents of Wi-Fi networks being affected by the campaign in hotels, conference centers, and other venues that use captive portals. In the company's view, corporate travelers are the primary targets, since compromise of their Microsoft 365 accounts would allow attackers access to sensitive company information. 

A related phishing campaign has been conducted since at least May 2026, while the campaign is believed to have been active since then. Microsoft's investigation indicates that the attackers compromised shared network infrastructure used by hospitality Wi-Fi providers, allowing them to manipulate DNS and HTTP traffic. Using this technique, they were able to redirect users to fraudulent Microsoft 365 login pages, phishing portals containing device codes, or fake software update screens when connecting to hotel Wi-Fi. 

It is believed that the attackers gained access to infrastructure shared across multiple captive portal deployments, rather than isolated compromises at individual hotels, allowing the campaign to target multiple hospitality locations without having to target each venue individually. 

The attacks were carried out by CornFlake and ChocoShell malware families that had previously been undocumented. As a Go-based remote access trojan (RAT), CornFlake provides long-term access to infected systems by allowing attackers to execute commands remotely, log data, capture screenshots, steal credentials from websites, steal session tokens from Microsoft 365, monitor clipboards, and exfiltrate data. 

A fake Windows update or security scan screen is displayed during the installation process of the malware to avoid suspicion. Several persistence mechanisms are also established to survive system reboots. 

In addition, Microsoft noted that CornFlake provides secure command-and-control communication through modern cryptographic techniques, as well as support for dynamic reconfiguration, which allows attackers to modify infrastructure and targets without redeploying the malware. Further, the RAT utilizes multiple persistence mechanisms in order to remain active despite the removal of one method by security tools. 

ChocoShell is a PowerShell credential stealer that targets cookie files, passwords, Microsoft 365 tokens, and stored Wi-Fi credentials stored in memory. Additionally, Microsoft discovered a management panel controlled by attackers, dubbed FruitStone, that allowed administrators to remotely manage compromised devices, execute PowerShell commands, browse files, and capture screenshots and keystrokes. 

The malware has been identified as targeting access and refresh tokens for Microsoft 365 and Azure Active Directory, thereby allowing attackers to potentially hijack enterprise sessions without requiring users to enter their credentials again. Using ClickFix social engineering techniques, researchers observed fake updates to browsers and operating systems that tricked users into installing malware through these updates. 

Through the same infrastructure, attackers have attempted to distribute malicious Android APK files as well. Amid the campaign, Microsoft observed the scheme expanding to include Microsoft Entra device code phishing, in which the victims are tricked into completing a legitimate Microsoft authentication process that unknowingly allows the attackers' session to be authorized instead of their own. 

Upon analyzing both malware families, Microsoft believes artificial intelligence tools likely contributed to their development as analysts identified extensive AI-generated comments throughout the source code, demonstrating an increasing trend in malware development by threat actors incorporating AI into their code.

The Microsoft team recommends that users consider hotel and conference Wi-Fi networks to be untrustworthy, use mobile or managed network connections whenever possible, avoid installing software provided through captive portals, and use phishing-resistant authentication methods such as passkeys and multi-factor authentication whenever possible to reduce the risk of compromise. 

The organization is also advised to disable Microsoft Entra device code authentication where it is not necessary and to avoid using corporate credentials when registering for guest Wi-Fi services. Furthermore, security experts advise against registering for guest Wi-Fi services using company email addresses, since this may expose enterprise identities to targeted phishing attempts. 

Using trusted public Wi-Fi networks for cyber-espionage is an extremely dangerous practice. As attackers continue to perfect phishing and malware techniques, organizations and travelers alike must take additional precautions when connecting to public networks and implement stronger authentication measures.