Microsoft warns Windows PC users of Russian hackers on hotel WiFi

Microsoft has raised an alert for Windows PC users regarding a sophisticated infiltration by Russian hackers, specifically targeting individuals connecting to hotel WiFi networks. The warning, issued on Friday, underscores the potential risks associated with public and hospitality network infrastructures.

“Organizations should assume that public and hospitality network infrastructure might not be trustworthy and should adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing,” Microsoft stated.

This advisory comes on the heels of Microsoft’s discovery of a global campaign dubbed CaptiveCrunch, which they attribute to Storm-2945, a faction within Russia’s Midnight Blizzard group. CaptiveCrunch is particularly focused on corporate travelers, employing tactics such as credential theft and malware distribution via compromised guest networks.

Microsoft has been tracking this campaign since May, noting its impact on hospitality and other guest networks utilizing captive portals across the globe. A report from ReliaQuest in July further highlighted that hackers were targeting Microsoft 365 users through compromised WiFi gateways, redirecting unsuspecting guests to counterfeit sign-in pages without the need for phishing emails or prior device compromise.

In a collaborative effort, Microsoft Threat Intelligence expressed gratitude to both Anthropic and OpenAI for their support during this investigation. The tech giant revealed that Storm-2945 has leveraged artificial intelligence to enhance the effectiveness of the CaptiveCrunch campaign.

Beyond targeting Windows systems with various malware variants, Microsoft Threat Intelligence has also detected signs that the threat actors may be extending their reach to Android devices. This includes instructions for users to download and install an APK file through similar deceptive techniques.

The modus operandi of these hackers involves manipulating hospitality networks to present fake verification checks, sign-in prompts, and software updates. These fraudulent pages often appear while users are connecting through a legitimate WiFi gateway, making it challenging for them to discern the authenticity of the connection.

In some instances, users are misled into Microsoft’s legitimate device-code authentication process, where hackers initiate a sign-in attempt and coax users into entering a code provided by them. If the user approves this request, Microsoft generates valid authentication tokens, granting access to the account without the need to steal passwords or circumvent multi-factor authentication.

Moreover, these attacks can deliver malware directly to users’ devices, masquerading as Windows updates. Microsoft has identified a specific Windows remote-access trojan (RAT) named CornFlake, which is engineered to record keystrokes, gather files, steal credentials and session tokens, and capture screenshots. CornFlake is also capable of hijacking a device’s audio and video functionalities for surveillance purposes, providing hackers with persistent access to compromised devices.

In light of these threats, Microsoft strongly advises travelers to exercise caution when using hotel, conference, airport, and other guest networks. Recommendations include:

  • Utilizing mobile hotspots or cellular connections for private connectivity.
  • Avoiding updates through captive portals.
  • Strengthening Conditional Access and employing phishing-resistant authentication methods.
  • Blocking device-code authentication when it is not necessary.
Winsage
Microsoft warns Windows PC users of Russian hackers on hotel WiFi