Hotel Wi-Fi Hijacked in Sophisticated Global Campaign to Deliver Surveillance Malware
Key points
- Microsoft has exposed a global internet hijacking campaign dubbed CaptiveCrunch, which targets captive portal gateways at hospitality venues and conference centers worldwide 12.
- Attributed to the Russian state-sponsored group Storm-2945 – a sub-cluster of Midnight Blizzard – the operation has been active across multiple countries since early May 12.
- Compromised Wi-Fi networks manipulate DNS responses to redirect users to fraudulent browser updates, fake security scans, and deceptive Microsoft 365 login pages 13.
- Victims risk infection by surveillance malware such as the CornFlake remote access trojan and the CocoShell in-memory PowerShell token stealer 13.
The Anatomy of the Hijack
When travelers log onto public Wi-Fi networks at hotels or conference centers, they typically rely on a captive portal to accept terms of service or enter room credentials before accessing the internet 3. In the newly disclosed CaptiveCrunch campaign, attackers manage to gain administrative control over the gateway equipment acting as the network’s DNS resolver 1. By forging DNS answers, the operators can seamlessly intercept and redirect automatic connectivity checks and web traffic without the user’s immediate knowledge 1.
Rather than relying on silent zero-day exploits, the operation heavily incorporates social engineering tactics known as ClickFix 14. Users attempting to browse the web are steered toward convincing doppelgänger domains – including fake Google security prompts and fraudulent Windows update screens – that instruct victims to execute manual commands or download malicious installers disguised as routine maintenance tools 124.
Payloads and Surveillance Arsenal
Once a victim is tricked into executing the attacker-supplied commands or payloads, the compromised network delivers sophisticated malware capable of deep system surveillance 1. One primary implant identified by researchers is CornFlake, a Go-based remote access trojan that masquerades as a legitimate background utility called Cloud Sync Service while establishing persistent system access 1.
CornFlake is equipped to capture screenshots, record microphone audio, log keystrokes, and harvest browser cookies and saved passwords – including credentials protected by advanced browser encryption 1. Additionally, researchers discovered ChocoShell, an in-memory PowerShell stealer designed specifically to harvest Microsoft 365, Azure Active Directory, and Web Account Manager access tokens from local cache files, enabling attackers to hijack authenticated sessions without relying on traditional browser cookies 1.
Attribution and Broader Context
Microsoft Threat Intelligence has linked the CaptiveCrunch operations to Storm-2945, an operational sub-cluster of Midnight Blizzard, which is also tracked as APT29 or Cozy Bear 12. The broader APT29 group has previously been tied by U.S. and U.K. authorities to Russia’s Foreign Intelligence Service (SVR) 1. While independent cybersecurity firm ReliaQuest noted tactical similarities to other Russian-linked threat groups such as APT28, investigations highlight a widespread pattern of infrastructure tampering 14.
Security analysts suggest that the campaign likely leveraged exposed remote management interfaces and weak administrative credentials to compromise hospitality networking gear, indicating that vulnerabilities may stem from shared services within the broader captive portal ecosystem rather than isolated hotel breaches 14.
Defending Against Gateway Attacks
As hospitality networks remain high-risk environments, cybersecurity experts urge travelers to minimize their trust in public guest Wi-Fi and rely instead on cellular data hotspots whenever feasible 24. For corporate travelers who must use public networks, security analysts recommend implementing an always-on, full-tunnel virtual private network (VPN) that routes DNS queries through secure corporate resolvers before local gateways can manipulate them 14.
Users should also exercise extreme caution regarding any software updates, browser patches, or troubleshooting utilities prompted through captive portals, and organizations are advised to review authentication controls – such as blocking device code flows via Conditional Access where unnecessary – to thwart credential abuse 12.
Companies mentioned: Microsoft, Google
Primary sources
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware (thehackernews.com) – Microsoft's comprehensive technical report details the CaptiveCrunch operation, the CornFlake and ChocoShell malware families, and attribution to Storm-2945.
- Microsoft warns hackers are targeting hotel Wi-Fi networks: What to know, how to protect yourself – ABC News – Breaking News, Latest News and Videos (abcnews.com) – ABC News reports on Microsoft's public warning regarding hospitality Wi-Fi manipulation and outlines recommended protective measures for travelers.
Further sources
Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware (techradar.com) – TechRadar breaks down the mechanics of captive portal hijacking and highlights the specific capabilities of the CornFlake and CocoShell infostealers.- Microsoft: Suspected Russian Hackers Are Targeting Logins Via Hotel Wi-Fi (pcmag.com) – PCMag discusses findings from ReliaQuest and Microsoft on ClickFix social engineering tactics and the exploitation of exposed Wi-Fi management interfaces.
- Russian spies turn public Wi-Fi into malware delivery systems (theregister.com) – The Register lists the public Wi-Fi malware delivery campaign among its industry news briefs alongside unrelated cybersecurity developments.

Powered by News Ranker