Cybersecurity

Microsoft: Russian Hackers Exploit Hotel Wi-Fi for Data Theft

Microsoft is alerting travelers to a sophisticated cyberattack, dubbed "CaptiveCrunch," by Russian state-sponsored hackers targeting hotel Wi-Fi networks. The group aims to steal sensitive user data via malicious downloads.

Joshua Ramos
Joshua Ramos covers cybersecurity for Techawave.
2 min read0 views
Microsoft: Russian Hackers Exploit Hotel Wi-Fi for Data Theft
Share

Microsoft is sounding the alarm on a widespread cyber campaign orchestrated by Russian state-sponsored hackers, which is actively compromising Wi-Fi networks in hospitality venues worldwide. The operation, codenamed "CaptiveCrunch," is being carried out by Storm-2945, a subset of the notorious Midnight Blizzard group, also known as APT29 or Cozy Bear. This group has been previously linked to Russia's Foreign Intelligence Service (SVR).

Microsoft Threat Intelligence first observed these widespread compromises of Wi-Fi networks at hotels and other hospitality organizations in May 2026. The attacks involve internet traffic manipulation, tricking users into downloading malicious files that can infect their devices and steal a trove of sensitive information, including browser cookies, passwords, and documents. In some cases, victims might be unknowingly redirected to fake login pages, potentially granting attackers access to their Microsoft 365 accounts, emails, and OneDrive storage.

How "CaptiveCrunch" Operates

The tactics employed by Storm-2945 specifically target users connected to Wi-Fi networks featuring captive portals – the login pages commonly found in hotels, airports, and conference centers. After a user attempts to connect, they are presented with deceptive prompts that appear to be legitimate system updates or security checks. These can masquerade as Windows Update screens, fake antivirus scans, DirectX installers, or browser update notifications. Some prompts may mimic Google's security checks, stating, "Our systems have detected unusual traffic from your computer network. Please complete the security check to access Google Search."

Upon clicking or downloading these seemingly innocuous files, users inadvertently install malware onto their devices. This malware is designed for comprehensive data exfiltration, capable of capturing keystrokes, screenshots, audio, and video feeds. It can also monitor the system clipboard and grant attackers remote control over the compromised device. This sophisticated approach allows the attackers to gather a wide range of personal and professional data, significantly increasing the risk of identity theft and corporate espionage.

The prolonged period between the initial observation of the threat in May and Microsoft's public disclosure in August has raised questions. While Microsoft declined to comment on the delay when approached by ABC News, the company emphasized the importance of user vigilance. The group's ability to operate undetected for months highlights the sophistication and persistence of state-sponsored hacking operations.

To mitigate these risks, Microsoft advises travelers and the public to exercise extreme caution when connecting to public Wi-Fi networks, particularly in hospitality settings. The company strongly recommends using private internet connections, such as personal mobile hotspots, whenever feasible. For those who must use public networks, the advice is to be highly skeptical of any unexpected pop-up windows requesting software downloads, updates, certificates, or network troubleshooting tools. A thorough review of information employees share when connecting to guest networks is also advised for organizations to bolster their internal cybersecurity measures.

This incident underscores the evolving landscape of cyber threats and the crucial need for continuous awareness and robust security practices. As remote work and travel become increasingly integrated into daily life, the security of public networks remains a critical vulnerability that both individuals and organizations must actively address. The ongoing efforts of groups like Midnight Blizzard continue to pose a significant challenge to global cybersecurity infrastructure.

Share