Microsoft warns travellers: Hotel Wi-Fi can expose passwords, audio and video
Microsoft has warned travelers about a cyberattack campaign called 'CaptiveCrunch' that targets hotel and public Wi-Fi networks. The campaign, linked to a Russian-affiliated group, uses fake captive portals to trick users into downloading malware or revealing credentials.
Microsoft’s Threat Intelligence team has issued a warning to travelers following a series of sophisticated cyberattacks targeting guest Wi-Fi networks at hotels and hospitality venues worldwide. The internet hijacking campaign, dubbed ‘CaptiveCrunch’, has been active since at least May and is attributed to Storm-2945, a sub-cluster claimed to be of the Russian hacking group Midnight Blizzard (also known as APT29 or Cozy Bear).According to Microsoft, the hacker group is executing "widespread but targeted" traffic manipulation attacks through Public guest networks and captive portal screens – the web pages that appear when users attempt to log onto hotel Wi-Fi or those at public places like airports, tourists venues and more. "To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries. ReliaQuest has identified this activity not only at hotels, but also conference centers and other shared venues, and assesses that the goal of this activity is to access the accounts of corporate travelers," said Microsoft in its report.How ‘CaptiveCrunch’ hacker attack worksThe hackers compromise the underlying Wi-Fi infrastructure of hospitality venues, redirecting unsuspecting guests through fake portals and malicious pop-ups. Once connected, victims are tricked into downloading malicious files or entering sensitive credentials under the guise of routine security checks.Microsoft revealed that the attacks takes place in two primary ways:Fake Browser Updates: Guests attempting to connect to hotel Wi-Fi may be presented with pop-ups prompting them to update their web browser or run network troubleshooting utilities. Some prompts mimic official Google security checks with warnings such as: "Our systems have detected unusual traffic from your computer network. Please complete the security check to access Google Search."Account Takeovers: In other instances, users are redirected to convincing fake login screens. Once credentials are submitted, the attackers gain access to the victim's Microsoft 365 accounts, granting them entry to private emails, OneDrive documents, and corporate networks.Once malware is installed on a target device, the hijackers gain broad control. Microsoft warned that Storm-2945 can capture keystrokes, record audio and video, take screenshots, steal browser cookies and stored passwords, and remotely operate the infected device.Microsoft listed a number of potential fake windows that may pop up upon logging into a compromised network, prompting users to download updates or patches. They include:* "winupdate": A Windows Update screen displaying the words "Working on updates… Don't turn off your computer"* "defender": A fake Windows Security virus scan* "directx": A "DirectX End-User Runtime Web Installer"* "vcredist": A Microsoft Visual C++ 2015-2022 Redistributable installer* "sysopt": A disk optimization utility* "netfix": A false Windows Network Diagnostics tool* "browser": A browser update prompt* "pdfview": A document viewer installerHow travelers can stay safeMicrosoft urges both individual travelers and corporate IT departments to exercise extreme caution on public networks, recommending the following protective measures:Use Cellular Hotspots: Avoid public or hotel Wi-Fi networks whenever possible; instead, rely on personal cellular hotspots or encrypted private connections.Ignore Unexpected Pop-Ups: Never download browser updates, security tools, network certificates, or software updates offered directly through hotel captive portals or unexpected browser pop-ups.Limit Data Sharing: Companies should review and restrict the sensitive information employees provide to hospitality providers when traveling or logging onto guest networks.Get the latest technology news and updates. Download the TOI App.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in