Microsoft has issued a warning to Windows PC users about Russian hackers targeting individuals using hotel WiFi networks. The campaign, named CaptiveCrunch and attributed to the Storm-2945 group, focuses on corporate travelers and employs tactics like credential theft and malware distribution through compromised guest networks. Microsoft has been monitoring this activity since May, noting its impact on hospitality networks utilizing captive portals. Hackers have been redirecting users to counterfeit sign-in pages to steal credentials without phishing emails. The threat may also extend to Android devices, with hackers using deceptive techniques to manipulate users into downloading malicious APK files. The hackers employ fake verification checks and sign-in prompts, sometimes misleading users into Microsoft's legitimate authentication process to gain access to accounts. Microsoft has identified a specific remote-access trojan named CornFlake, which can record keystrokes, steal credentials, and capture screenshots. Recommendations for travelers include using mobile hotspots, avoiding updates through captive portals, strengthening authentication methods, and blocking unnecessary device-code authentication.