Homepage Technology Microsoft uncovers Russian-linked attacks on hotel Wi-Fi networks

Microsoft uncovers Russian-linked attacks on hotel Wi-Fi networks

Russia flag wifi sign hotel coffee laptop
Shutterstock

Researchers are continuing to examine a cyber campaign that highlights evolving techniques used in digital espionage. The findings underscore the growing importance of securing internet connections while traveling and working remotely.

Hotel Wi-Fi sign-in pages are being exploited in a targeted espionage campaign aimed at travelers of intelligence interest.

Microsoft researchers say Russian state-linked hackers compromised hospitality networks and manipulated captive-portal traffic to deliver malware and steal account credentials.

The campaign, called CaptiveCrunch, has been active since early May 2026. Microsoft attributed it to Storm-2945, a subgroup of Midnight Blizzard, which US and UK authorities have linked to Russia’s Foreign Intelligence Service.

Fake update trap

A captive portal is the registration page guests must use before connecting to a hotel network. Attackers manipulated DNS requests and unencrypted HTTP traffic, sending selected users through infrastructure under their control.

The redirected travelers were shown fraudulent browser or operating-system checks. Following the instructions and running the downloaded file could install CornFlake, a Windows remote-access Trojan.

According to Microsoft, CornFlake can record keystrokes, steal passwords and session tokens, access a computer’s webcam and record microphone audio.

Such attacks can be particularly dangerous for employees working away from company-managed networks, where familiar security controls may not be available.

Common infrastructure

Investigators have not established how the hospitality systems were initially compromised. Because several affected locations used similar equipment or management technology, Microsoft is examining whether the breaches originated from common infrastructure.

The company also found signs that the developer of a separate malicious script, called ChocoShell, may have used AI-assisted code generation. Microsoft did not conclude that artificial intelligence powered the wider operation.

Travelers are advised to treat hotel Wi-Fi as untrusted, reject software updates offered through sign-in portals and use a trusted VPN or cellular connection when handling sensitive information.

European sanctions

The findings were published amid separate European efforts to disrupt Russia’s broader cyber ecosystem.

On July 13, 2026, the European Union sanctioned nine individuals and four entities accused of carrying out, enabling or facilitating malicious cyber activity.

Britain announced its first coordinated cyber-sanctions package with the EU on the same day. The measures were not presented as a response to CaptiveCrunch.

Sources: Microsoft Threat Intelligence, Council of the European Union and UK Foreign, Commonwealth & Development Office.

Ads by MGDK