Russian Hackers Breached Wi-Fi Networks at Hotels and Airports and Are Targeting Travelers

06.10.2026 5 minutes Author: Newsman

A Russia-linked hacker group known as Midnight Blizzard gained access to Wi-Fi networks in hotels, airports, conference centers, and other public places. The attackers intercept travelers’ traffic, redirect them to fake login pages, and attempt to steal credentials or install malware.

Microsoft reported a new wave of the CaptiveCrunch campaign, which it links to Storm-2945, a separate cluster associated with Midnight Blizzard. The activity resumed in late September, and researchers believe the hackers may have retained access to companies that manage Wi-Fi infrastructure for the hospitality industry.

According to Black Lotus Labs, three North American companies that manage Wi-Fi networks for seven of the ten largest hotel chains in the United States may have been compromised this summer. Researchers believe these were not isolated attacks against individual hotels, but rather compromises of service providers that gave the hackers access to a large number of customer networks at once.

Microsoft Threat Intelligence said the campaign’s return suggests that multiple managed service providers serving the hospitality industry may have been compromised.

“Continued access to these providers likely enabled the operation to resume so quickly,” Microsoft said.

How the Attack Works Through Public Wi-Fi

After gaining control of a Wi-Fi gateway, attackers can manipulate DNS and HTTP traffic and redirect users to infrastructure they control. Victims may then see a fake authentication portal designed to look like a legitimate hotel or airport Wi-Fi login page.

Through these pages, hackers attempt to steal credentials and OAuth tokens. In other cases, users are shown fake prompts claiming they need to update Windows, their browser, a driver, complete a security check, or pass a CAPTCHA. The instructions are designed to trick users into downloading and running a malicious file themselves.

A previous ReliaQuest report noted that after taking control of a Wi-Fi gateway, attackers can silently redirect users to their own infrastructure to steal credentials. This activity has been observed since at least June 2026.

The campaign also makes use of AI. Microsoft found signs that artificial intelligence was used at different stages of the operation, including during malware development. In the latest attacks, researchers identified a Rust version of the CornFlake infostealer that shows signs of further development with the use of AI.

In addition to stealing data, the attackers distribute fully featured remote access trojans for Windows. This malware can collect files and keystrokes, steal passwords and session tokens, monitor the connection of external storage devices, access the microphone and camera, and provide hackers with a remote command shell on the infected device.

Microsoft also observed signs of potential attacks targeting Android. Some fake ClickFix pages included instructions telling Android users to download and install an APK file.

Attacks Have Been Coming in Waves Since the Beginning of the Year

Microsoft first detected signs of the campaign in February 2026, when the attackers began preparing DNS resolvers and infrastructure for adversary-in-the-middle attacks. By early May, researchers were already observing large-scale but selective traffic manipulation in networks using captive portals.

In late June, a wave of attacks began involving the first managed Wi-Fi service provider, which researchers refer to as MSP 1. A second wave linked to MSP 2 started on July 23, followed by activity through MSP 3 the very next day.

Black Lotus Labs separately observed activity from roughly a dozen IP addresses in the Las Vegas area several weeks before the Black Hat and DEF CON conferences.

“We separately observed activity from roughly a dozen IP addresses geolocated to the Las Vegas area several weeks ahead of the Black Hat/DEF CON conferences,” the researchers said.

Over the course of the summer, specialists identified about 70 victim IP addresses associated with the campaign. Each address could represent a separate compromised network, although the actual number of physical locations may have been lower.

Black Lotus Labs notes that the three identified Wi-Fi service providers work with seven of the ten largest hotel chains in the United States. Activity was observed in the US and Mexico, while ReliaQuest also reported cases in Saudi Arabia and India.

Despite earlier public reports about the campaign, the attacks did not stop. In late September, Microsoft once again detected Storm-2945 activity in hotel networks, where the attackers were manipulating traffic and using captive portals to reach potential victims.

Microsoft Warns Against Trusting Public Wi-Fi

Microsoft recommends that travelers treat Wi-Fi networks in hotels, airports, conference centers, casinos, and other public places as potentially unsafe. Whenever possible, users should rely on mobile data, a personal hotspot, eSIM, or other private connection methods instead.

“Do not download software updates, certificates, browser updates, network troubleshooting tools, or security tools offered through a captive portal or other unexpected web prompts,” Microsoft warns.

A VPN with private DNS can provide an additional layer of protection by creating an encrypted tunnel and making it more difficult to redirect DNS requests at the level of a compromised Wi-Fi router.

For business travel, Microsoft also recommends company-managed routers or mobile hotspots that automatically establish an encrypted connection to trusted corporate infrastructure before users access sensitive resources.

Background

Midnight Blizzard, also known as Cozy Bear or APT29, has long been linked to Russian foreign intelligence. The group is known for supply-chain attacks, in which the attackers compromise an IT service provider or another trusted third party instead of directly targeting the final organization.

One of the best-known operations linked to the group was the SolarWinds attack in 2020. In the years that followed, the hackers also targeted IT providers, cloud services, and other infrastructure that could give them access to a larger number of organizations.

CaptiveCrunch essentially follows the same approach, but this time the entry point is companies that manage Wi-Fi networks in hotels and other places where travelers regularly connect.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.
↑