Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices with espionage malware, researchers have found.
In a report published Friday, Microsoft said the activity is linked to Storm-2945, a sub-cluster of the Russian espionage group Midnight Blizzard believed by Western intelligence agencies to be connected to Russia's Foreign Intelligence Service (SVR).
The campaign, first observed by Microsoft in early May, targets hotels and other hospitality venues that require guests to log into Wi-Fi through so-called captive portals — web pages users must access before connecting to the internet.
According to the researchers, the attackers manipulate internet traffic on compromised networks to redirect victims to fake Microsoft login pages or fraudulent browser and operating system update screens designed to deliver malware.
The cybersecurity firm ReliaQuest, which first disclosed the activity in July, said the operation has affected hotels and other hospitality organizations across multiple U.S. cities, as well as in India and Saudi Arabia. The company said conference centers and other shared venues have also been affected, with corporate travelers appearing to be the primary targets.
The hackers use two main techniques to compromise victims' devices, according to Microsoft.
In one, victims are redirected to fake Microsoft authentication pages, allowing the attackers to intercept login credentials and gain access to Microsoft 365 accounts.
In the other, users are presented with fake browser or operating system update pages that persuade them to download malware using so-called ClickFix social engineering techniques, in which victims are tricked into installing the malicious software themselves.
Microsoft identified two primary malware families used in the campaign.
The first, known as CornFlake, is a remote access trojan that gives operators persistent control of infected Windows computers. Once installed, it can collect files, record keystrokes, steal passwords and authentication tokens, capture audio and video, detect removable media such as USB drives, and allow operators to remotely control compromised systems.
The second, ChocoShell, is an information stealer designed to harvest browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and Wi-Fi credentials. While CornFlake is intended to maintain a long-term foothold on victim devices, ChocoShell is designed to quickly extract credentials that can be used to access cloud accounts and other online services.
Microsoft said the operation may be expanding beyond Windows computers. Some of the fake update pages include instructions directing Android users to download and install a malicious application.
Microsoft's attribution differs from ReliaQuest's earlier assessment, which said the tactics resembled those used by APT28, also known as Fancy Bear or Forest Blizzard, the Russian military intelligence hacking group previously linked to router-based campaigns targeting Microsoft 365 accounts.
Earlier in April, Britain's National Cyber Security Centre warned that APT28 hackers had been exploiting vulnerable internet routers to hijack web traffic and conduct espionage by compromising poorly secured or outdated network devices.
Microsoft instead attributed the activity to Storm-2945, which it describes as part of Midnight Blizzard — also known as APT29, Cozy Bear, and BlueBravo — an espionage group that primarily targets governments, diplomatic missions, and organizations in the defense, energy, media, and political sectors in support of Russian foreign policy objectives.
While the current activity has largely focused on hotels, ReliaQuest previously warned that any organization operating captive portal networks — including airports, conference centers, co-working spaces, universities, healthcare facilities, and event venues — could become a target.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



