If you're a business traveler, listen up. Microsoft just dropped a warning that should make you think twice before connecting to that "free" hotel Wi-Fi.
Russian state-sponsored hackers have been running a global campaign called CaptiveCrunch since early May 2026. The group behind it? Storm-2945 — a sub-cluster of Midnight Blizzard (APT29), the same crew linked to Russia's Foreign Intelligence Service.
Here's how it works — and why it's so dangerous.
The Attack, Explained Simply
You check into a hotel. You open your laptop. You connect to the Wi-Fi. A login page pops up — the usual captive portal.
Except this time, it's not the hotel's page.
The attackers have compromised the network's DNS and HTTP traffic. They redirect you to either:
- A fake Microsoft login page that steals your credentials, or
- A fake browser/OS update that installs malware
And here's the scary part: because these pages appear through the hotel's legitimate gateway, you have almost no way of telling they're fake.
What They're After
Corporate travelers are the prime targets — financial services, legal, healthcare, energy sectors. The attackers want Microsoft 365 credentials, cloud data, and persistent access to corporate environments.
Microsoft found two previously unknown malware families:
CornFlake — a remote access trojan that gives attackers persistent control. It logs keystrokes, captures screenshots, records audio and video, steals browser credentials, and executes remote commands.
ChocoShell — a PowerShell-based infostealer that runs entirely in memory (harder to detect). It extracts browser passwords, Microsoft 365 tokens, Wi-Fi credentials, and session cookies.
Both report back to a command-and-control platform called FruitStone.
The attackers even used AI to assist with development — ChocoShell's code contains detailed developer comments that researchers say suggest AI assistance.
It's Not Just Windows
While Windows users are the primary target, the campaign also targets Android devices. Some fake update pages include instructions to download and install malicious APK files.
And it's not just hotels. Conference centers and other venues using captive portals have been compromised.
What You Can Do
Microsoft's advice is blunt: treat hotel and public Wi-Fi as untrusted.
Here's what that means in practice:
- Use your phone as a hotspot instead of hotel Wi-Fi
- Use a VPN — a full-tunnel VPN, not just a browser extension
- Never click on pop-ups asking you to update your browser or OS while on hotel Wi-Fi
- Enable phishing-resistant authentication (like FIDO2 keys) for Microsoft 365
- Organizations should consider blocking device-code authentication where not required
Bottom Line
This isn't a theoretical threat. It's happening right now, globally. The campaign has been active since May and Microsoft says it's more widespread than initially reported.
Next time you travel, think before you click "Connect." That free Wi-Fi might cost you a lot more than you bargained for.
Tags:
Technology
