HomeRisk ManagementsMidnight Blizzard Affects Travelers Through Captive Portals

Midnight Blizzard Affects Travelers Through Captive Portals

Published on

spot_img

Cybersecurity Alert: Captive Portals Hijacked to Distribute Malware

Recent findings have revealed a troubling cybersecurity trend involving captive portals on hotel and conference Wi-Fi networks. These portals have been manipulated to route unsuspecting guests through an adversarial infrastructure, serving up bogus browser and operating system updates that install malware associated with Russian espionage.

On July 31, Microsoft Threat Intelligence released research detailing a campaign named "CaptiveCrunch," which has reportedly been active since early May. This operation has been attributed to Storm-2945, a subgroup of the notorious hacking collective known as Midnight Blizzard. The US and UK governments have previously linked Midnight Blizzard—also referred to as APT29, the Dukes, or Cozy Bear—to Russia’s Foreign Intelligence Service, known as the SVR.

While Microsoft is still probing how exactly these portals were compromised, analysts note that there are common characteristics in the hardware and management systems of the networks under attack. Such commonalities may suggest that the breaches resulted from access to centralized services within the captive portal ecosystem rather than isolated compromises at individual venues.

The Methodology: Fake Updates and Connectivity Checks

The threat actors are employing sophisticated tactics to trap users. Instead of waiting for individuals to navigate to a website, these attackers are responding to automated connectivity checks that browsers and operating systems initiate when connecting to a new network. These checks typically produce pages suggesting necessary updates for the user’s browser or operating system.

The malicious pages utilize ClickFix techniques, presenting visitors with fake verification failures alongside instructions that encourage paste-and-run tactics. Microsoft also noted that some of these pages delivered an APK file, hinting at a possible targeting of Android users.

As of July 16, certain malicious pages began directing users into device code authentication flows. Attackers provided a code for users to input on an authentic Microsoft sign-in page, making the overall scheme appear legitimate. Though Microsoft acknowledges that this technique is not new, embedding it within a captive portal enhances the illusion of authenticity, making users more likely to comply.

ReliaQuest, a cybersecurity firm, reported part of this illicit activity on July 23, discovering that it was occurring in hotels, conference centers, and similar venues. The primary targets of these attacks are corporate travelers, who often rely heavily on public Wi-Fi networks for their connectivity.

Tools of the Trade: Three Malicious Implementations

The primary malware being deployed is known as CornFlake, a remote access trojan (RAT) built using the Go programming language. This sophisticated malware masquerades as a legitimate process by displaying a fake progress window during installation. After the installation completes, it registers as a Windows service under the guise of a Cloud Sync Service, making detection more difficult.

CornFlake incorporates a suite of features: it can log keystrokes, capture screenshots, and monitor microphone and webcam activity. Additionally, it is equipped to steal browser credentials and offers a remote shell, along with a watchdog routine designed to restore any persistence mechanisms that security defenders might remove.

Another tool utilized in this campaign is a PowerShell infostealer called ChocoShell. This particularly insidious malware operates entirely within memory, disabling the Antimalware Scan Interface (AMSI) before siphoning off sensitive information such as browser cookies, saved passwords, Microsoft 365 single-sign-on tokens, and Wi-Fi credentials. The developer of ChocoShell has offered commentary that highlights specific Microsoft detection signatures, suggesting that the malware may have been generated with the aid of artificial intelligence.

The operation is orchestrated from a web panel named FruitStone, which is presented as a fictitious enterprise cloud product, further enhancing the deceptive narrative behind the campaign.

Recommendations for Users

In light of these alarming developments, Microsoft has issued several recommendations for individuals who frequently utilize hotel, conference, and airport wireless networks. Users are advised to regard public Wi-Fi as inherently untrustworthy and prefer cellular or eSIM connectivity when possible. Importantly, it is recommended to avoid installing software suggested through captive portals and to block device code flows where they are unnecessary. The deployment of passkeys is also encouraged as an added layer of security.

The extensive implications of these attacks underscore the pressing need for increased vigilance among users. As attackers continuously evolve their tactics, it is imperative for both individuals and organizations to stay informed and proactive in their cybersecurity measures.

Source link

Latest articles

Huntress Offers Free RMM-Blocking Feature to All Customers Amid 277% Surge in Attacks

Huntress Launches Free RMM Guard Amid Surge in Cybersecurity Attacks In a significant move to...

Russian Intel Hacks Hotel Wi-Fi

Russian Intelligence Hackers Target Hotel Wi-Fi Networks ...

Korea’s Largest Telco KT Fined $39 Million Following Femtocell Campaign

In a significant cybersecurity incident, South Korea's largest telecommunications provider, KT (formerly Korea Telecom),...

Snowflake Introduces Cortex AI Gateway

Snowflake Unveils Cortex AI Gateway: A Solution for Managing AI Interactions in Enterprises In an...

More like this

Huntress Offers Free RMM-Blocking Feature to All Customers Amid 277% Surge in Attacks

Huntress Launches Free RMM Guard Amid Surge in Cybersecurity Attacks In a significant move to...

Russian Intel Hacks Hotel Wi-Fi

Russian Intelligence Hackers Target Hotel Wi-Fi Networks ...

Korea’s Largest Telco KT Fined $39 Million Following Femtocell Campaign

In a significant cybersecurity incident, South Korea's largest telecommunications provider, KT (formerly Korea Telecom),...