Cover image: Traveller using a laptop and smartphone connected to public hotel Wi-Fi — photo by Muhammad Raufan Yusup muhraufan, CC0, via Wikimedia Commons.
Travellers connecting to hotel Wi-Fi are the target of an active, state-sponsored hacking campaign, Microsoft Threat Intelligence warned in an advisory published on 31 July 2026. The company says Storm-2945, a sub-cluster of the Russian foreign-intelligence-linked group Midnight Blizzard (APT29), has been manipulating the sign-in portals of hotel and conference-centre Wi-Fi networks in several countries since at least early May 2026.
Microsoft calls the operation CaptiveCrunch. Instead of setting up fake "evil twin" hotspots, the attackers compromised the genuine captive portals — the sign-in pages guests see when they join a property's network — and redirected traffic to phishing pages that mimic Microsoft 365 logins or to fake software-update prompts that install surveillance malware. The wider phishing campaign dates back to February 2026, and security firm ReliaQuest publicly disclosed related DNS-hijacking activity on 23 July, according to Microsoft. The practical takeaway for anyone on the road: treat hotel Wi-Fi as hostile, use mobile data where you can, and never install anything a guest network asks you to.
What did Microsoft's hotel Wi-Fi warning actually say?
The advisory describes "widespread but targeted" traffic-manipulation attacks on hospitality networks, aimed at corporate travellers at hotels, conference centres and other shared venues. Victims connecting to an affected network had their DNS and HTTP traffic silently rerouted through attacker-controlled infrastructure.
Notably, Microsoft found "notable commonalities in the equipment and management systems" across the affected properties, suggesting the group gained access to shared services within the captive-portal ecosystem — upstream network kit used by many venues — rather than breaking into hotels one by one. That is what makes this campaign unusually dangerous: guests cannot spot it by checking the network name, because the compromised network is the hotel's real one.
From 16 July 2026, Microsoft says, the campaign added device-code phishing: landing pages steer guests to a legitimate Microsoft sign-in screen and prompt them to enter a code — which quietly authorises the attacker's session on the victim's Microsoft 365 account, a technique previously used by the related Midnight Blizzard sub-cluster Storm-2372.
How does the CaptiveCrunch hotel Wi-Fi attack work?
In plain English, the attack unfolds in three ways once a guest joins a compromised network, per Microsoft's report:
- Fake Microsoft 365 login pages. The portal redirects guests to convincing phishing pages that harvest work email credentials.
- Device-code phishing. Guests are walked through entering an attacker-supplied code on the real Microsoft sign-in site, handing over an authenticated session without ever typing a password on a fake page.
- Fake update prompts ("ClickFix"). Pop-ups disguised as browser or Windows repair prompts instruct the guest to run a "verification" command — via cmd.exe or PowerShell — which actually installs malware. Microsoft also notes indications of parallel targeting of Android devices with prompts to install rogue APK files.
This is an industrialised version of long-standing hotel Wi-Fi risks, executed at the infrastructure layer — where the guest has no visual clue anything is wrong.
What malware is being spread through hotel networks?
Microsoft named three custom tools in the campaign — and, based on extensive comments in the code, assesses that AI tools were likely used to develop the malware, BleepingComputer reported:
| Tool | What it is | What it does to victims |
|---|---|---|
| CornFlake | Windows remote-access trojan written in Go | Keylogging, screenshots, audio and video surveillance, clipboard and USB monitoring, browser credential theft, file exfiltration; hides behind fake Windows Update and Windows Security scan windows and persists as a bogus "Cloud Sync Service" |
| ChocoShell | In-memory PowerShell infostealer | Steals browser cookies and saved passwords, Microsoft 365 single-sign-on tokens and stored Wi-Fi credentials; disables Windows' Antimalware Scan Interface (AMSI) while it runs |
| FruitStone | Web-based command-and-control panel | Operator dashboard — branded as a "CloudSync Console" and found running without authentication protections — used to manage infected devices and harvested data |
The stolen session cookies and SSO tokens matter as much as passwords: they can let attackers into corporate cloud accounts even where multi-factor authentication is switched on.
How can travellers protect themselves on hotel Wi-Fi?
Microsoft's recommendations, plus standard travel-security practice, boil down to a checklist:
- Prefer mobile data over guest Wi-Fi. Microsoft explicitly advises private connectivity, such as a phone hotspot, over public Wi-Fi. A local or regional data plan is now cheap and instant to set up — our eSIM guide for international travel covers how.
- Never install anything a Wi-Fi network asks you to. No captive portal legitimately needs you to run a command, "verify" your browser or install an update or APK. Close the page and disconnect.
- Never enter work credentials — or a sign-in code someone else gave you — via a hotel portal. Device-code prompts that originate from a guest network are a red flag even when the sign-in page itself is genuine.
- Turn off auto-join for public networks and use a reputable VPN — remembering a VPN does not stop you typing a password into a phishing page.
- Use phishing-resistant sign-in. Microsoft urges passwordless options such as passkeys, and tells organisations to block device-code flow wherever possible.
Companies should also brief road warriors before trips and, Microsoft advises, minimise unnecessary disclosure of employee identities, organisational affiliations and travel details when booking accommodation. Note that cyber incidents are generally outside standard trip cover — see our guide to what travel insurance actually covers.
The episode lands as travel becomes ever more digital, from biometric boarding at airports to AI-driven trip planning — a reminder that the connectivity layer beneath all of it still deserves basic scepticism.
Frequently asked questions
Is hotel Wi-Fi safe to use in 2026?
Treat it as untrusted, Microsoft says — even the hotel's genuine network, since CaptiveCrunch compromised real captive portals rather than fake hotspots. Casual browsing over HTTPS is relatively low-risk; entering work credentials, approving sign-in codes or installing anything prompted by the network is not.
Does a VPN protect against these hotel Wi-Fi attacks?
Partially. A VPN encrypts your traffic and blunts DNS and HTTP manipulation once connected, but it cannot stop you voluntarily typing a password into a phishing page or running a malicious "fix-it" command. Combine a VPN with mobile data, passkeys and healthy suspicion of pop-ups.
What should I do if I entered my login on a hotel Wi-Fi portal?
Change the password immediately from a trusted connection, revoke active sessions and sign out of all devices, and tell your IT team so they can check for suspicious sign-ins and reset tokens. Because the campaign steals session cookies and SSO tokens, a password change alone may not be enough.
How can I spot a fake captive portal or update prompt?
Red flags include requests to install software or certificates, prompts to run commands or paste text into a terminal, sign-in pages asking for corporate email passwords, and device-code screens you did not initiate. When in doubt, disconnect and confirm the network name and sign-in process with the front desk.
Sources
- Microsoft Threat Intelligence — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
- Help Net Security — Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
- BleepingComputer — Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Post a comment