AUTO-UPDATED

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft Threat Intelligence has identified the CaptiveCrunch campaign, where the Russian-linked group Storm-2945 compromises hotel and conference Wi-Fi networks to deploy malware and steal corporate user credentials.

Key Points

  • Storm-2945, a sub-cluster of the Russian SVR-linked Midnight Blizzard, has been active since May 2026.
  • Attackers manipulate DNS and HTTP traffic on captive portal networks to redirect guests to malicious landing pages.
  • The campaign deploys CornFlake, a sophisticated Windows remote access trojan, and ChocoShell, an in-memory PowerShell infostealer.
  • Malicious pages impersonate legitimate software updates or verification prompts to trick users into executing payloads.
  • Attackers are utilizing device code phishing to bypass multi-factor authentication and hijack active Microsoft 365 and Azure sessions.

Why it Matters

This campaign highlights a significant vulnerability in shared network infrastructure, potentially exposing corporate travelers to widespread credential theft and system compromise. Organizations should restrict device code authentication flows and advise employees to avoid public Wi-Fi in favor of cellular data to mitigate these risks.
Securityaffairs.com Published by Pierluigi Paganini
Read original