Microsoft has issued a warning to organizations regarding the risks associated with public and hospitality network infrastructures, citing a new hacking threat from Russian cyber actors targeting travelers for malware distribution and credential theft. This warning follows the identification of a global campaign named CaptiveCrunch, linked to Storm-2945, which has been targeting corporate travelers since early May by exploiting compromised guest networks. Attackers are manipulating hospitality networks to facilitate credential theft and malware delivery, using tactics such as redirecting network traffic to counterfeit sign-in pages. The campaign affects both Windows and Android devices and employs techniques that include presenting fake verification checks and software updates. Some victims have been misled into participating in Microsoft’s legitimate device-code authentication process, allowing attackers to gain access to accounts without stealing passwords. Microsoft advises travelers to treat guest networks as untrusted and recommends using mobile hotspots, avoiding updates through captive portals, and enhancing security measures. Malicious tools identified include the Windows remote-access trojan (RAT) named CornFlake, which can steal credentials, record keystrokes, and hijack audio and video capabilities.