Microsoft has confirmed that a Russian state-sponsored hacking group is actively hijacking hotel and venue Wi-Fi networks to steal Microsoft 365 credentials and infect traveler devices with malware. If your employees connect to hotel, conference, or airport Wi-Fi without a plan, this is the moment to put one in place.
| Quick Answer: Microsoft has identified a campaign called “CaptiveCrunch,” run by the Russian group Storm-2945, that compromises hotel and venue Wi-Fi captive portals (the login pages guests see before getting online) to redirect travelers to fake update prompts and phishing pages. Clicking these prompts can hand attackers your Microsoft 365 credentials, browser data, and in some cases, full device control. Businesses should treat all public Wi-Fi as untrusted and route travel traffic through a company VPN or personal hotspot. |
What Microsoft Found
Microsoft Threat Intelligence published an advisory identifying widespread compromise of Wi-Fi networks at hotels and other hospitality venues, an operation it first observed in May and nicknamed “CaptiveCrunch.” Microsoft attributes the activity to Storm-2945, a Russian state-sponsored hacking group it describes as a sub-cluster of Midnight Blizzard. Midnight Blizzard, also tracked in the security industry as APT29 or Cozy Bear, is a group Microsoft and other researchers have linked to Russia’s Foreign Intelligence Service, and it has been behind several major intrusions into U.S. and European government and corporate networks over the past decade. This is not a low-level criminal operation; it’s a nation-state actor with a long track record.
The attack doesn’t rely on phishing emails or malware already on the device. Instead, the hackers compromise the hotel’s underlying Wi-Fi infrastructure and its captive portal, the login page guests see before getting online, often by entering a room number or agreeing to terms of use. Once a network is compromised, guest traffic can be redirected through attacker-controlled servers.
From there, travelers may see convincing pop-ups disguised as routine Windows updates, browser update prompts, or fake Google security checks. Clicking through can install malware that Microsoft has named CornFlake, a remote access trojan that lets attackers control the device, and ChocoShell, a PowerShell-based infostealer that harvests saved passwords, browser cookies, and documents. Together, they’re also capable of recording keystrokes, capturing screenshots, and in some cases activating a device’s microphone or camera.
In other cases, the attackers skip malware entirely and go straight for the credentials. Some victims are guided through what looks like a legitimate Microsoft device-code sign-in flow. If the traveler enters an attacker-supplied code, Microsoft issues a valid authentication token, and the attacker gains account access without ever stealing a password or needing to beat multi-factor authentication.
Microsoft says the campaign isn’t limited to hotels. Conference centers, airports, and other venues with guest Wi-Fi logins are also at risk, and there are signs the group is targeting Android devices as well.
Why This Matters for Your Business
A compromised Microsoft 365 account isn’t just an inconvenience for the traveling employee. It’s a foothold into their email, OneDrive, and anything connected to their identity, including the accounts and systems your broader team relies on. For companies with employees who travel regularly for client meetings, conferences, or site visits, this campaign turns a routine hotel check-in into a potential entry point for a state-sponsored threat actor.
This is also a reminder that a Wi-Fi password doesn’t equal a secure network. A guest network requiring a room number or last name to log in can still sit on infrastructure that’s already compromised upstream, invisible to the traveler and, in some cases, to the venue itself.
What Microsoft Recommends
Microsoft’s guidance is straightforward, and it’s guidance every business with traveling staff should be reinforcing now:
- Treat hotel, conference, airport, and other guest Wi-Fi networks as untrusted, regardless of whether they require a password.
- Avoid installing software updates, drivers, certificates, or apps through prompts that appear while connected to public Wi-Fi. Legitimate updates come through your device’s own settings, not a browser pop-up.
- Don’t click unexpected security alerts, “verification” screens, or update prompts that appear immediately after connecting to a guest network.
- Use a company VPN or a personal mobile hotspot instead of hotel or venue Wi-Fi when handling business accounts or sensitive data.
- If a suspicious pop-up appears, close it without clicking anything inside it, and report it to IT or your security team.
How Amplix Can Help
Guidance is only as good as the training and controls behind it. Amplix’s cybersecurity advisory practice works with clients to build the policies, endpoint protections, and employee awareness programs that turn advisories like this one into actual protection, not just an email nobody reads twice. That includes conditional access policies that can flag or block sign-ins from unfamiliar networks, and awareness training built around real, current threats instead of generic phishing examples.
Frequently Asked Questions
Is hotel Wi-Fi safe to use for work?
Not without precautions. Microsoft’s CaptiveCrunch advisory shows that even password-protected hotel Wi-Fi can sit on compromised infrastructure. For business use, route sensitive traffic through a VPN or personal hotspot rather than connecting directly.
What is CaptiveCrunch?
CaptiveCrunch is the name Microsoft gave to a hacking campaign in which Storm-2945, a Russian state-sponsored group, compromises hotel and venue Wi-Fi captive portals to redirect users to phishing pages and malware downloads.
Who is Midnight Blizzard?
Midnight Blizzard, also known as APT29 or Cozy Bear, is a Russian state-sponsored hacking group linked to Russia’s Foreign Intelligence Service. Storm-2945, the group behind CaptiveCrunch, is described by Microsoft as a sub-cluster of Midnight Blizzard.
Can hotel Wi-Fi steal my Microsoft 365 password?
Yes. In this campaign, compromised networks can redirect users to fake sign-in flows that harvest credentials or trick users into approving a fraudulent device-code authentication request, giving attackers access without ever stealing a password directly.
Does a VPN protect me on hotel Wi-Fi?
A VPN encrypts your traffic and routes it away from the local network, which significantly reduces exposure to this type of attack. It’s one of the most effective and lowest-effort protections available to traveling employees.
Talk to Amplix About Your Travel Security Policy
If your team travels for client meetings, conferences, or site visits, now is the time to confirm your VPN policy, conditional access rules, and employee awareness training cover this kind of threat.
Reach out to our cybersecurity practice to talk through where your organization stands.