Russian state-sponsored hackers are compromising hotel Wi-Fi networks worldwide to harvest Microsoft 365 credentials and deploy espionage malware. According to Microsoft, the campaign utilizes compromised captive portals to manipulate internet traffic, redirecting unsuspecting travelers to fraudulent update screens and credential-harvesting pages.
Travelers connecting to public networks at hotels, conference centers, and shared venues face heightened security risks following a sophisticated cyberespionage campaign. Discovered by researchers and detailed by Microsoft, the operation intercepts legitimate Wi-Fi access pathways to target corporate and government users away from their home offices.
Captive Portal Exploitation and Traffic Manipulation
Rather than relying on rogue Wi-Fi hotspots or standalone phishing domains, the threat actors infiltrate the legitimate captive portals that guests rely on to access the internet. As users log into authentic hotel networks, the infrastructure behind the scenes redirects web traffic to fraudulent authentication prompts or deceptive browser and operating system update screens.

The campaign primarily targets business travelers, government employees, and representatives from non-governmental organizations. According to Microsoft, the actor known as Storm-2945—a subgroup of the Midnight Blizzard espionage collective—is orchestrating the activity. While Microsoft attributes the operation to Midnight Blizzard, earlier disclosures from the cybersecurity firm ReliaQuest noted tactical similarities to router-based campaigns previously linked to APT28, also known as Fancy Bear.
Malware Deployment and Credential Harvest Strategies
Once victims are successfully redirected, the attackers deploy distinct techniques depending on the device and target environment. For Microsoft 365 users, fraudulent authentication prompts abuse device code authentication processes or present fake login interfaces designed to capture active single sign-on tokens and access credentials.

When targeting desktop computers with fake software updates, the operators rely on ClickFix social engineering methods that trick users into executing malicious installation steps themselves. Microsoft identified two primary malware families utilized to maintain persistence and extract sensitive files from compromised systems.
According to Microsoft, while CornFlake is intended to maintain a long-term foothold on victim devices, ChocoShell is designed to quickly extract credentials that can be used to access cloud accounts and other online services.
CornFlake operates as a remote access trojan capable of recording keystrokes, harvesting passwords, capturing audio and video feeds, and monitoring removable USB storage devices on Windows computers. In contrast, ChocoShell functions as an information stealer targeted at browser cookies, Wi-Fi credentials, and cloud authentication tokens. Furthermore, recent monitoring indicates the operation is expanding beyond desktop environments. Security researchers noted that some malicious landing pages include instructions directing Android users to download and install a malicious application.
Defending Shared Infrastructure and Public Networks
Security agencies and private researchers emphasize that public and hospitality networks cannot be treated as secure infrastructure. In April, Britain’s National Cyber Security Centre issued warnings regarding threat actors exploiting vulnerable routers to compromise poorly secured network equipment.
To mitigate these risks, technical experts advise organizations and individuals to adopt robust preventative measures. Recommendations include deploying phishing-resistant multi-factor authentication methods such as hardware security keys and passkeys, monitoring corporate networks for anomalous device registrations, and relying exclusively on trusted virtual private networks when traveling.
Worth a look