Russian Intelligence Hackers Target Hotel Wi-Fi Networks

In a disturbing trend highlighted by recent reports, hackers are exploiting hotel Wi-Fi networks throughout the United States, India, and Saudi Arabia to engage in credential theft, data exfiltration, and malware dissemination. This alarming information has been revealed by both Microsoft and cybersecurity firm ReliaQuest. Such malicious activities underline the increasing sophistication of cyber threats targeting unsuspecting travelers who often rely on public networks for their connectivity needs.
Microsoft’s threat intelligence unit initiated its investigation into this emerging threat in early May of this year. The cyber activities have been linked to a sub-cluster known as Storm-2945, which is part of the notorious Midnight Blizzard group, associated with Russia’s Foreign Intelligence Service. This group is commonly referred to by various names, including APT29, Cozy Bear, and BlueBravo, marking its long-standing reputation in the realm of cyberespionage.
According to Microsoft’s findings, Storm-2945 is currently executing “widespread but targeted traffic manipulation” campaigns that are particularly focused on the hospitality sector’s networks, specifically those utilizing captive portals. Microsoft has aptly designated this malicious campaign as “CaptiveCrunch.”
In special focus research conducted by ReliaQuest in July, they tracked incidents of DNS poisoning attacks targeting hotel Wi-Fi networks, which were attributed to Unit 26165 of the Russian Main Intelligence Directorate—also recognized by names such as APT28, Forest Blizzard, and Fancy Bear. Microsoft’s analysts noted that while there are similarities in the tactics, techniques, and procedures (TTP) employed by both groups, it is essential to recognize that CaptiveCrunch is a separate threat actor altogether.
Reports from Microsoft and ReliaQuest reveal that these hackers have been compromising captive portal infrastructures within hospitality networks to conduct adversary-in-the-middle campaigns. This technique allows them to redirect victims towards one of two counterfeit attack pathways—a fraudulent Microsoft authentication page or a deceptive browser software update page. The overarching goal of these tactics is twofold: to either steal user credentials or to deliver malicious software onto victims’ devices. ReliaQuest posits that these hackers may gain access through management interfaces that are inadvertently exposed to the internet.
During these attacks, Microsoft identified two distinct malware types being disseminated: the Cornflake persistent remote access Trojan and the ChocoShell infostealer, which specializes in harvesting and extracting sensitive user credentials along with authentication tokens. Such malware poses a significant risk to both individual users and organizations alike, highlighting the importance of cybersecurity awareness during travel.
In addition to hotels and common traveler spaces, the attacks have also targeted conference centers and other corporate venues, intensifying concerns about network security in areas frequented by professionals. Microsoft experts further noted that the “consistent coding standard and descriptive commentary” present within Storm-2945’s operations could indicate the involvement of artificial intelligence tools to assist in campaign execution or code generation. This suggests an unsettling evolution in the techniques employed by cybercriminals.
As a preventative measure, cybersecurity researchers have advised corporate travelers, especially those attending professional conferences or utilizing hotel accommodations, to verify all URLs prior to entering personal or corporate credentials. They recommend using personal VPNs when on public Wi-Fi networks or opting for mobile hotspots, satellite connections, or eSIM-based cellular data connections. Equally important is to avoid random software updates or downloads that may be prompted through captive portals, as they could serve as entry points for malware.
For hospitality providers, including hotels, conference centers, and airports, the focus must be on securing network infrastructures. This includes diligent monitoring of DNS settings and gateway devices to mitigate potential threats. By taking these measures, the hospitality industry can aim to protect both its networks and its patrons from becoming unwitting victims of cyber threats.