Amid a rise in cyberattacks, even something as simple as a hotel’s WiFi network might not be safe.
Microsoft’s threat intelligence team uncovered a hacking campaign called CaptiveCrunch, run by a group known as Storm-2945, part of the larger Russian state-sponsored operation Midnight Blizzard, also called APT29 or Cozy Bear.
Since early May, the group has been hijacking WiFi networks at hotels, conference centres, and other shared venues around the world. They quietly redirect guests’ Internet traffic through hacker-controlled servers, enabling them to steal login credentials or sneak malware onto devices – without the traveller ever noticing anything was wrong.
Louis Eichenbaum, federal chief technology officer at ColorTokens, told Inc. that part of what makes this particular tactic so effective is that travellers have been conditioned to overlook the warning signs. “Business travellers are conditioned to expect unfamiliar login pages, certificate warnings, and network prompts when connecting to public WiFi,” he said. “That creates an environment where malicious activity blends into normal behaviour.”
Additionally, these venues bring together high-value targets from government, critical infrastructure, defence, health care, finance, and technology, all in one place, meaning a single compromised wireless network can give attackers access to hundreds or thousands of potential victims at once.
This combination of soft security and concentrated, high-profile targets is also what makes these venues so attractive for such operations.
Microsoft has not disclosed the total number of users or organisations affected by the CaptiveCrunch campaign. When reached for comment, Microsoft said it had nothing further to add and referred Inc. to its blog post on the matter.
“To date, Microsoft has identified widespread compromise of WiFi networks at hospitality-related organisations and other networks serviced by captive portal equipment in several countries,” Microsoft said in a recent report. “ReliaQuest has identified this activity not only at hotels, but also conference centres and other shared venues, and assesses that the goal of this activity is to access the accounts of corporate travellers.”
Some CaptiveCrunch landing pages go a step further by tricking guests into thinking they’re a part of Microsoft’s legitimate device sign-in process, the same shortcut normally used to log into devices like smart TVs with a short code instead of a password.
The attacker initiates a login on their end, and then has the victim enter a code on Microsoft’s real sign-in page. While the victim believes they’re logging into their own account, they have actually approved the attacker’s session instead – one that’s already cleared multifactor authentication, since the victim just completed that step.
Matt Radolec, field chief technology officer at Varonis, told Inc. the technique works well because hidden code runs on the user’s device and extracts active login tokens stored temporarily in memory. These tokens are designed to expire after a set period, typically a convenience that keeps users logged in without repeated password entry. But once stolen, that same convenience becomes a liability: The token can often be reused without triggering another identity check, making a compromised device easy to exploit.
The reason this keeps happening, according to Radolec, comes down to how little attention hotel and conference WiFi actually gets. “They are public networks meant for guests to browse and do whatever they want,” he said. “These networks are often not secured or monitored at all.”
That gap in oversight fits into a broader shift attackers have been making in recent years, away from email and toward the login process itself. “It’s another example of attackers shifting away from traditional phishing and toward compromising trusted user experiences,” Eichenbaum added. “As organisations improve email security and MFA adoption, adversaries are increasingly targeting the authentication process itself.”
Radolec recommends travellers take a few precautions: Connect through an always-on VPN, think twice before clicking links, and keep your computer’s software updated. Above all, he said, never assume public WiFi is safe, or that the websites accessed through it can be trusted. – Inc./Tribune News Service
