Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials

Microsoft warns Russian hackers are exploiting hotel Wi-Fi to deliver malware, steal credentials, and compromise corporate travelers’ cloud accounts worldwide.

Written By
LT
Liz Ticong
Aug 4, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Connecting a work laptop to hotel Wi-Fi could expose corporate credentials and sensitive data. Microsoft has uncovered a Russian state-backed campaign that uses compromised hospitality networks to target travelers.

Tracked as CaptiveCrunch, the campaign has affected networks in several countries since early May 2026. Malicious prompts appear during the normal connection process, allowing them to pass as part of the venue’s Wi-Fi setup.

Researchers attribute the activity to Storm-2945, a subgroup of Midnight Blizzard, the espionage group linked by the US and UK governments to Russia’s Foreign Intelligence Service.

Hotel Wi-Fi turns into a malware trap

Browsers and operating systems automatically test a new Wi-Fi connection to determine whether it requires a captive-portal login. Storm-2945, the Russian state-backed subgroup behind the campaign, manipulates DNS and unencrypted HTTP traffic during that check, redirecting selected users to pages under attacker control.

Microsoft described the operation as involving “widespread but targeted traffic manipulation attacks.”

Victims may see a fake Windows or browser update, or a bogus driver or security fix. Other versions use ClickFix prompts that instruct the user to paste and run malicious commands. Device-code phishing sends victims to Microsoft’s legitimate authentication page, where entering an attacker-provided code authorizes the attacker’s session instead of the traveler’s.

Joining the network alone does not necessarily infect a device. Attackers still need the traveler to run a file, execute a command, or approve a sign-in. The request appears when an additional connection step may seem credible. Researchers also found instructions directing Android users to install an APK, although the report documents the Windows activity in greater detail.

How the affected captive-portal networks were first compromised remains unknown. Similar equipment and management systems raise the possibility that Storm-2945 accessed a shared service used by multiple hotels or venues instead of breaching every location separately.

Advertisement

Stolen access can follow travelers home

CornFlake, the campaign’s persistent Windows remote-access trojan, gives operators extensive control over an infected laptop. It can capture keystrokes and screenshots or activate the microphone and webcam. Operators can search connected storage and collect files, while a remote command shell enables continued access.

ChocoShell extracts browser cookies and saved passwords. It also targets Microsoft 365 single sign-on tokens and stored Wi-Fi credentials. FruitStone provides a central dashboard for managing infected devices and reviewing collected information.

For security professionals, CaptiveCrunch creates both an endpoint and identity incident. Cleaning or reimaging the laptop addresses the local foothold, but it does not invalidate stolen session tokens or terminate a device-code session authorized for the attacker. Cloud access may remain valid after the employee checks out and reconnects elsewhere.

Depending on the traveler’s permissions, a stolen cloud session could expose corporate email and shared files. Attackers could also use the compromised account for internal phishing or further cloud access, allowing one encounter during a business trip to develop into a larger intrusion.

Travelers and security teams can reduce exposure

Microsoft recommends using cellular data through an eSIM or personal hotspot instead of guest Wi-Fi whenever practical. Travelers who must use a hotel network should:

  • Reject software updates, drivers, or certificates offered through the Wi-Fi portal.
  • Avoid troubleshooting utilities or commands supplied by a connection page.
  • Verify updates through Windows, the browser, or another trusted application.
  • Report unexpected Microsoft authorization requests without approving them.

ReliaQuest found that an always-on, full-tunnel VPN can stop the gateway-level DNS poisoning used in the campaign when all traffic, including DNS, enters the tunnel before reaching the hotel gateway. Protection depends on proper VPN configuration and security practices. A VPN started manually after the portal or malicious prompt appears does not provide the same protection.

Advertisement

Security teams should:

  • Block device-code authentication wherever it is unnecessary.
  • Apply Conditional Access and phishing-resistant authentication.
  • Restrict connections to unmanaged Wi-Fi networks on company devices.
  • Use endpoint detection and response telemetry to hunt for executable or archive files created shortly after a captive-portal connectivity check.
  • Review risky Entra sign-ins and suspicious OAuth activity following a reported encounter.

Counts of affected venues and travelers have not been disclosed. Limited scope data leaves organizations without a clear measure of how widely CaptiveCrunch has reached hospitality networks.

Read more: An alleged UK police platform breach could expose contact details useful for targeted phishing and social engineering.

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.