Technology

Russian SVR Hackers Hijack Hotel Wi-Fi Networks to Spy on Corporate Travelers

Microsoft uncovers a state-sponsored campaign named CaptiveCrunch using compromised captive portals, AI-assisted malware, and MFA bypass tactics.

Russian state-backed cyber-espionage group Midnight Blizzard has compromised hotel and conference center Wi-Fi networks across several countries, using intercepted traffic to drop AI-assisted malware and bypass multi-factor authentication on corporate travelers’ devices.

Tracked by Microsoft Threat Intelligence under the campaign name CaptiveCrunch, the activity has been live since at least early May. The operation is carried out by Storm-2945, a subgroup of Midnight Blizzard—the SVR-linked unit previously responsible for the 2020 SolarWinds supply chain breach and the late 2023 intrusion into top Microsoft executive email accounts. Rather than breaching individual hotels one by one, the threat actors appear to have compromised shared management equipment within the hospitality industry’s captive portal ecosystem, gaining control over DNS and HTTP traffic.

Once a target connects to a compromised guest network, the gateway silently redirects their web traffic to attacker-controlled infrastructure. Travelers attempting to access corporate services are shown fake Microsoft 365 login portals that leverage device-code authentication. In this scheme, the attacker initiates a session and prompts the victim to enter a code into a legitimate Microsoft authorization page. Because the user logs in through official channels, the flow completely bypasses multi-factor authentication defenses, granting hackers access without needing to steal passwords or session tokens.

Visitors who encounter the rogue portals are also prompted to download fake Windows Update files, Defender patches, DirectX installers, or browser updates. BleepingComputer identified two specialized tools deployed in the campaign: CornFlake, a Go-based remote access trojan that establishes persistence under the disguise of a “Cloud Sync Service,” and ChocoShell, an in-memory PowerShell infostealer. CornFlake provides operators with keylogging, webcam and microphone capture, clipboard monitoring, and credential theft capabilities. Code analysis of ChocoShell revealed unusually detailed comments, indicating the hackers used artificial intelligence to generate parts of the malware script.

An investigation by cybersecurity firm ReliaQuest discovered affected network gateways operating in major US cities, India, and Saudi Arabia. Affected users spanned sectors including energy, finance, legal, healthcare, retail, and professional services, pointing to broad corporate intelligence gathering rather than a single targeted industry. Researchers noted that the operation also shows indicators of targeting Android mobile devices through malicious APK installation prompts.

The tactic mirrors the decade-old Darkhotel campaigns, where state-sponsored actors infected high-ranking executives through hotel Wi-Fi networks, as well as a recent campaign by Russian group Forest Blizzard that hijacked thousands of small office and home routers to spy on Microsoft 365 users.

To defend against CaptiveCrunch, Microsoft urges travelers to treat all public networks—including those in hotels, airports, and convention centers—as untrusted, recommending the use of personal cellular hotspots, full-tunnel VPNs, and encrypted DNS. Organizations are advised to enforce phishing-resistant passkeys and disable Entra ID device-code authentication across systems where it is not strictly required.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button