Connecting a work laptop to hotel Wi-Fi could expose corporate credentials and sensitive data. Microsoft has uncovered a Russian state-backed campaign that uses compromised hospitality networks to target travelers.
Tracked as CaptiveCrunch, the campaign has affected networks in several countries since early May 2026. Malicious prompts appear during the normal connection process, allowing them to pass as part of the venue’s Wi-Fi setup.
Researchers attribute the activity to Storm-2945, a subgroup of Midnight Blizzard, the espionage group linked by the US and UK governments to Russia’s Foreign Intelligence Service.
Hotel Wi-Fi turns into a malware trap
Browsers and operating systems automatically test a new Wi-Fi connection to determine whether it requires a captive-portal login. Storm-2945, the Russian state-backed subgroup behind the campaign, manipulates DNS and unencrypted HTTP traffic during that check, redirecting selected users to pages under attacker control.
Microsoft described the operation as involving “widespread but targeted traffic manipulation attacks.”
Victims may see a fake Windows or browser update, or a bogus driver or security fix. Other versions use ClickFix prompts that instruct the user to paste and run malicious commands. Device-code phishing sends victims to Microsoft’s legitimate authentication page, where entering an attacker-provided code authorizes the attacker’s session instead of the traveler’s.
Joining the network alone does not necessarily infect a device. Attackers still need the traveler to run a file, execute a command, or approve a sign-in. The request appears when an additional connection step may seem credible. Researchers also found instructions directing Android users to install an APK, although the report documents the Windows activity in greater detail.
How the affected captive-portal networks were first compromised remains unknown. Similar equipment and management systems raise the possibility that Storm-2945 accessed a shared service used by multiple hotels or venues instead of breaching every location separately.
Stolen access can follow travelers home
CornFlake, the campaign’s persistent Windows remote-access trojan, gives operators extensive control over an infected laptop. It can capture keystrokes and screenshots or activate the microphone and webcam. Operators can search connected storage and collect files, while a remote command shell enables continued access.
ChocoShell extracts browser cookies and saved passwords. It also targets Microsoft 365 single sign-on tokens and stored Wi-Fi credentials. FruitStone provides a central dashboard for managing infected devices and reviewing collected information.
For security professionals, CaptiveCrunch creates both an endpoint and identity incident. Cleaning or reimaging the laptop addresses the local foothold, but it does not invalidate stolen session tokens or terminate a device-code session authorized for the attacker. Cloud access may remain valid after the employee checks out and reconnects elsewhere.
Depending on the traveler’s permissions, a stolen cloud session could expose corporate email and shared files. Attackers could also use the compromised account for internal phishing or further cloud access, allowing one encounter during a business trip to develop into a larger intrusion.
Travelers and security teams can reduce exposure
Microsoft recommends using cellular data through an eSIM or personal hotspot instead of guest Wi-Fi whenever practical. Travelers who must use a hotel network should:
- Reject software updates, drivers, or certificates offered through the Wi-Fi portal.
- Avoid troubleshooting utilities or commands supplied by a connection page.
- Verify updates through Windows, the browser, or another trusted application.
- Report unexpected Microsoft authorization requests without approving them.
ReliaQuest found that an always-on, full-tunnel VPN can stop the gateway-level DNS poisoning used in the campaign when all traffic, including DNS, enters the tunnel before reaching the hotel gateway. Protection depends on proper VPN configuration and security practices. A VPN started manually after the portal or malicious prompt appears does not provide the same protection.
Security teams should:
- Block device-code authentication wherever it is unnecessary.
- Apply Conditional Access and phishing-resistant authentication.
- Restrict connections to unmanaged Wi-Fi networks on company devices.
- Use endpoint detection and response telemetry to hunt for executable or archive files created shortly after a captive-portal connectivity check.
- Review risky Entra sign-ins and suspicious OAuth activity following a reported encounter.
Counts of affected venues and travelers have not been disclosed. Limited scope data leaves organizations without a clear measure of how widely CaptiveCrunch has reached hospitality networks.
Read more: An alleged UK police platform breach could expose contact details useful for targeted phishing and social engineering.





