ThinkPatternGet the app
Story
TECHNOLOGY · AUG 2, 2026

Russian Hackers Target Hotel Wi-Fi to Steal Corporate Credentials

Microsoft Corporation and ReliaQuest warn that Russian state-sponsored hackers are compromising hotel Wi-Fi networks globally to steal credentials and deploy surveillance malware.

A global hacking campaign dubbed CaptiveCrunch is targeting corporate travelers by compromising Wi-Fi gateways and captive portals at hotels, airports, and conference centers. Microsoft Corporation and cybersecurity firm ReliaQuest identified the operation, which began as early as May 2026. The attacks are attributed to Storm-2945, a sub-cluster of the Russian state-sponsored threat actor Midnight Blizzard, which is linked to the Russian Foreign Intelligence Service.

Attackers hijack networking hardware to redirect users to fraudulent Microsoft 365 login pages, fake Google security checks, or bogus software update screens. These tactics deceive users into providing passwords or approving device code authentication prompts to bypass multifactor authentication. The campaign deploys two primary malware variants: CornFlake, a remote-access trojan capable of recording keystrokes and activating cameras and microphones, and CocoShell, a PowerShell credential stealer.

While the campaign primarily targets Windows PCs used by professionals in the financial, legal, health care, and energy sectors, researchers found indications that Android devices are also being targeted via APK installations. Affected regions include the United States, India, and Saudi Arabia. Microsoft Corporation advises travelers to avoid guest networks and software updates on public Wi-Fi, recommending the use of personal cellular hotspots, travel routers, or full-tunnel VPNs to mitigate risks.


Reported across 199 outlets
Actors
Microsoft CorporationReliaQuestForeign Intelligence Service

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play