Heightened Security Warnings for Business Travelers
In a significant shift in security guidance, Microsoft has urged organizations to approach public and hospitality network infrastructures with caution, suggesting they may not be reliable. This warning comes in light of a new hacking threat linked to Russian cyber actors, specifically targeting travelers worldwide for malware distribution and credential theft.
The alert follows the identification of a global campaign named CaptiveCrunch, attributed to Storm-2945, a subgroup of the notorious Midnight Blizzard. This campaign has been actively targeting corporate travelers since early May, utilizing compromised guest networks to facilitate credential theft and malware delivery.
According to Microsoft, the threat landscape has evolved, with attackers manipulating hospitality networks and other guest networks that utilize captive portals. A report from ReliaQuest in July highlighted similar tactics, revealing that attackers were exploiting compromised Wi-Fi gateways to target Microsoft 365 users. By redirecting network traffic, these attackers could lead unsuspecting guests to counterfeit sign-in pages without prior phishing attempts or direct compromises of their devices.
In an intriguing development, Microsoft Threat Intelligence acknowledged the contributions of Anthropic and OpenAI in their investigation, particularly in relation to the use of artificial intelligence by Storm-2945 to enhance their threat operations. The campaign not only targets Windows systems with various malware variants but also appears to extend its reach to Android devices, employing techniques reminiscent of those used in previous attacks.
The attackers have ingeniously compromised hospitality infrastructure to present fake verification checks, sign-in prompts, and software updates. This deception is particularly insidious, as these fraudulent pages are displayed while users connect through legitimate Wi-Fi gateways, making it challenging for individuals to discern the threat.
Some victims have been misled into participating in Microsoft’s legitimate device-code authentication process. By initiating a sign-in attempt, attackers can convince victims to enter codes supplied by them. If the victim approves this request, Microsoft issues valid authentication tokens, allowing the attacker to access the victim’s account without needing to steal passwords or bypass multi-factor authentication directly.
While ReliaQuest’s research primarily focused on credential theft, Microsoft has indicated that these attacks can also deliver malware directly to victims’ devices, significantly expanding the scope of the threat. Notably, the campaign has been known to distribute malware disguised as Windows updates.
Among the malicious tools identified is the Windows remote-access trojan (RAT) named CornFlake. This RAT is engineered to steal credentials and session tokens, record keystrokes, collect files, and capture screenshots. Additionally, it can hijack a device’s audio and video capabilities for surveillance purposes, granting attackers persistent access to compromised devices.
In light of these developments, Microsoft strongly advises travelers to treat hotel, conference, airport, and other guest networks as untrusted. Recommendations include utilizing mobile hotspots or cellular connections for private connectivity, avoiding updates through captive portals, enhancing Conditional Access and phishing-resistant authentication, and blocking device-code authentication when it is not necessary.