Microsoft warns hackers targeting hotel Wi-Fi: How to protect yourself

Microsoft recently issued a warning to travelers that hackers are targeting Wi-Fi networks in hotels and related hospitality venues with “broad but targeted” network traffic manipulation attacks.

According to Microsoft Threat Intelligence, a network hijacking operation dubbed “CaptiveCrunch” was reported on their website. Microsoft attributed this operation to the Russian state-supported hacker group Storm-2945, which is a “subset” of the cyber attacker group “Midnight Blizzard” (also known as “APT29” or “Cozy Bear”).

Microsoft indicated that “Midnight Blizzard” is associated with the Russian foreign intelligence service (SVR).

The tech giant confirmed that “hotel-related institutions’ Wi-Fi networks have been widely invaded” (along with other network attacks) and stated that such attacks were first detected as early as May.

Microsoft also shared information about the threat, the methods used by hackers to carry out hijackings, and best practices for public prevention against such threats.

According to Microsoft, the Storm-2945 hackers are targeting hotels and other hospitality venues globally, specifically focusing on users who connect to Wi-Fi networks through visitor login pages (known as “captive portals”).

Users may be prompted to download malicious files, through which hackers infect user devices with malware to steal browser cookies, passwords, documents, and other information. Hackers can record keystrokes, capture screenshots, record audio and video, monitor clipboard content, and even remotely control devices.

In some cases, users attempting to access infected networks may be redirected to fake login pages; once on these pages, hackers may gain access to users’ Microsoft 365 account permissions, thus accessing their emails and OneDrive data.

Microsoft stated that users faced with such threats may encounter various false pop-ups designed to confuse them, making it difficult to detect the scam. Microsoft listed various types of false pop-ups that may appear when users log into infected networks, prompting them to download updates or patches.

According to Microsoft, users may also receive prompts to update their browser due to “automatic connection checks.” These false “connection checks” may resemble the interface of the Google browser, displaying messages such as “Verify your identity” and “Our system has detected abnormal traffic on your computer network, please complete a security check to access Google search.” Upon following the prompts, hijackers can gain access to users’ devices and remotely control them.

Microsoft advised users to remain vigilant when using visitor networks in hotels, conference venues, airports, or other public places. The company recommended using private network connections (such as mobile hotspots) as much as possible rather than public Wi-Fi.

If users must handle sensitive data such as work or online banking in hotels or airports, it is recommended to turn off Wi-Fi and use a mobile hotspot to share the network connection with their laptops, which is currently the safest practice. If using hotel Wi-Fi is unavoidable, it is advised to immediately enable a reputable encrypted VPN after successful connection to prevent subsequent traffic from being eavesdropped or manipulated by hackers.

Microsoft also urged the public to exercise caution when encountering pop-up requests, avoiding “downloading software updates, certificates, browser updates, network troubleshooting tools, or security utilities displayed through captive portals or other unexpected web prompts.” Legitimate Wi-Fi login pages will never ask users to log into their Microsoft 365 accounts or update software. If faced with these requests, users should promptly close the web page.

Furthermore, ensuring that your important accounts are enabled with Passkey (key) can effectively block hackers from using phishing pages to steal your passwords.

Additionally, Microsoft issued warnings to various institutions, requesting them to “review what information their employees have provided to hospitality service providers (such as hotels) when connecting to visitor networks.”

(Reference to ABC News reporting)