Russia-Linked ‘Midnight Blizzard’ Group Hijacks Hotel Wi-Fi With CaptiveCrunch

Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks

Cyberattack Targets Travelers’ Data via Compromised Hotel Wi-Fi Networks

A Russia-linked hacking group identified as Midnight Blizzard has exploited hotel and conference Wi-Fi networks globally, redirecting users to phishing pages and fake software updates to steal sensitive data. Microsoft’s analysis of the campaign, named CaptiveCrunch, indicates it targets traveling employees across various sectors rather than specific industries. The attack involves compromising captive portal gateways in multiple countries, including the U.S., India, and Saudi Arabia, affecting financial services, legal, healthcare, energy, and retail organizations. Attackers deploy tools like CornFlake, a Windows remote access trojan capable of keylogging and credential theft, and ChocoShell, an in-memory PowerShell tool for stealing browser cookies and Microsoft 365 tokens. The campaign also shows potential targeting of Android devices through APK file prompts. While Microsoft did not specify the exact number of affected venues or individuals, security firm ReliaQuest’s prior findings highlight widespread compromise in major cities. This incident underscores vulnerabilities in public Wi-Fi infrastructure and the growing threat of cyberattacks against mobile professionals.

Leave a Reply

Your email address will not be published. Required fields are marked *