Particle.news
Download on the App Store

Microsoft Says Russian-Linked Hackers Are Hijacking Hotel and Airport Wi‑Fi to Steal Logins

The company warns attackers are altering captive‑portal and DNS responses to push fake sign‑in pages that install spyware and seize account access.

Overview

  • Microsoft has named the campaign CaptiveCrunch and attributes it to a Russian‑linked cluster called Storm‑2945 that targets guest Wi‑Fi at hotels, airports and conference venues.
  • Attackers manipulate captive‑portal gateways and DNS/HTTP responses to redirect users to realistic phishing pages that capture Microsoft credentials, device codes and OAuth tokens.
  • Researchers say the campaign can also prompt fake software updates to deliver malware families reported as CornFlake and ChocoShell, which can log keystrokes, capture files and enable remote surveillance.
  • Microsoft and security vendors advise treating guest networks as untrusted, using private hotspots or enterprise travel routers, running an always‑on full‑tunnel VPN with a killswitch, and enabling phishing‑resistant authentication or passkeys.
  • Investigators are still probing how captive‑portal systems were first compromised and say common equipment and management links may point to shared services being abused, a finding that raises risks for corporate travelers and long‑term espionage.