Russian state-backed hackers are using compromised hotel and conference WiFi networks to spy on business travelers, according to new research from Microsoft, which says the campaign is designed to steal corporate credentials and establish long-term access to government and enterprise environments.

 

 

Rather than attacking organisations directly, the threat actors are targeting employees while they travel, taking advantage of public wireless networks that many professionals rely on during business trips. Microsoft attributes the activity to Storm-2945, a subgroup associated with the Russian espionage operation Midnight Blizzard, also known as NOBELIUM or Cozy Bear.

The campaign, which Microsoft calls CaptiveCrunch, has reportedly been active since at least May. Investigators say the attackers compromise legitimate captive portal systems, the web pages commonly used by hotels, conference centres and other venues to authenticate guests before granting internet access.

Once a victim connects to the network, the attackers redirect them to convincing Microsoft sign-in pages or display fraudulent prompts encouraging them to install Windows or browser updates. Instead of legitimate software, those downloads install malware that gives the attackers long-term access to the infected device.

Microsoft says the campaign primarily targets organisations in the United States and Europe, with governments, diplomatic organisations, non-governmental organisations and IT service providers among the main targets. By compromising employees while they are travelling, the attackers can obtain credentials and monitor activity before attempting to move deeper into corporate environments.

The malicious software observed in the campaign includes CornFlake, a remote access trojan, and ChocoShell, a PowerShell-based information stealer. According to Microsoft’s analysis, the malware is capable of collecting Microsoft 365 credentials, session cookies, saved passwords, and files while maintaining persistent access to compromised systems. Researchers also observed capabilities that allow the malware to record keystrokes and, in some cases, access microphones and cameras. Microsoft said a limited number of Android devices were also targeted during the operation.

Security experts believe the campaign demonstrates a broader shift in cyber espionage tactics. Instead of focusing exclusively on enterprise infrastructure, attackers are increasingly targeting environments where employees connect outside the office and may be less cautious.

Michael Centrella, Head of Public Policy at SecurityScorecard, said compromised hospitality networks can become effective surveillance platforms because travellers often assume hotel internet services are trustworthy. He noted that attackers can silently intercept communications, harvest credentials and maintain long-term access without immediately triggering alerts inside the victim’s organisation. Centrella added that public WiFi networks at airports, universities and healthcare facilities could present similar risks if their captive portals were compromised.

Microsoft recommends avoiding software updates offered through public WiFi login pages or unexpected browser pop-ups, instead installing updates only through trusted operating system mechanisms. The company also advises users to verify the authenticity of WiFi login portals before entering credentials and, where possible, use enterprise-managed hotspots or trusted mobile connections instead of public wireless networks.

For organisations, Microsoft recommends treating business travel as a higher-risk activity by requiring phishing-resistant multi-factor authentication, enforcing VPN use on untrusted networks, monitoring for suspicious account activity and limiting privileged access for employees while travelling. The company says these measures can help reduce the risk of credential theft and long-term compromise if attackers target staff outside the corporate network.

Leave a Reply