2 Remove Virus

Hackers turn trusted hotel Wi-Fi networks into traps for travelers

A cyberespionage campaign targeting hotel and public Wi-Fi networks may be broader than initially believed, with new research suggesting attackers compromised technology providers to gain access to multiple customer networks at once.

 

 

The campaign, known as CaptiveCrunch, targets the familiar Wi-Fi login pages travelers see at hotels, conference centers, and similar locations. Instead of creating a fake wireless network, the attackers can compromise infrastructure supporting the legitimate Wi-Fi service.

That distinction makes the attack particularly difficult for travelers to recognize. A person can connect to the correct hotel network and still be redirected toward infrastructure controlled by attackers.

Black Lotus Labs researchers identified nearly 70 IP addresses associated with affected organizations. Around 40 communicated with infrastructure used by the attackers for DNS-related activity, while another 30 communicated with systems associated with attempts to steal authentication information. Researchers cautioned that these numbers do not necessarily represent 70 individual locations.

The investigation found another important connection. The affected organizations appeared to use three North American managed service providers, or MSPs. These companies provide technology and network services to other businesses, including major hotel groups.

Researchers believe the attackers first compromised these providers and then used their trusted access to reach downstream customers. The three MSPs are preferred providers for seven of the ten largest hotel chains in the United States, potentially giving attackers a much larger pool of networks to target.

Once access to Wi-Fi infrastructure was established, attackers could manipulate internet traffic and redirect selected travelers. Victims could encounter fake authentication pages designed to steal Microsoft account access or be pushed toward malicious software.

The operation has been linked to Storm-2945, a group Microsoft considers part of the Russian state-backed Midnight Blizzard operation. Microsoft says it has also seen the campaign return in late September, suggesting the attackers retained access to upstream providers.

For travelers, the danger is that nothing about the Wi-Fi network itself necessarily looks suspicious. A hotel Wi-Fi portal should not require someone to install a software update, enter an unexpected Microsoft device code, or approve an unexplained authentication request.

The campaign demonstrates how compromising one technology provider can give attackers access to many organizations at once, turning ordinary and legitimate Wi-Fi networks into potential entry points for targeted attacks.