Microsoft Uncovers Global Hotel Wi-Fi Malware Campaign


phishing hotel microsoft 365
Image credit: Microsoft

Microsoft says Midnight Blizzard is targeting hotel and conference Wi-Fi networks worldwide to steal credentials and deliver malware to travelers.

The Russian state-sponsored hacking group, also known as APT29, reportedly operates the campaign through Storm-2945, one of its associated sub-groups.

Microsoft tracks the activity as CaptiveCrunch and believes the campaign has operated since at least May 2026.

Attackers compromise captive portal traffic

The attackers target hospitality networks that use captive portals, which normally ask guests to sign in or accept terms before accessing the internet.

Midnight Blizzard tampers with DNS and HTTP traffic to redirect connected devices toward malicious websites. Microsoft found evidence that the attackers may have compromised shared network infrastructure rather than individual routers or access points.

The company has not determined how the attackers initially gained access to the affected networks.

Hotel networks have faced similar threats before. Attackers previously hijacked hotel Wi-Fi to steal Microsoft 365 accounts, while Microsoft recently warned about phishing attacks targeting hotels in Japan.

Fake Microsoft 365 pages steal credentials

Victims connecting to compromised Wi-Fi can land on fake Microsoft 365 sign-in pages that collect usernames and passwords.

The attackers also use device-code phishing to abuse Microsoft Entra ID authentication. This method convinces users to enter a legitimate-looking device code that grants the attackers access to their accounts.

Microsoft observed attackers actively using these redirection methods from July onward.

Fake updates install CornFlake malware

Some victims see fraudulent browser or Windows update pages instead of conventional phishing forms.

These pages use ClickFix-style instructions that persuade users to copy commands, launch installers, or run malicious files. Microsoft also found signs that attackers targeted Android devices with malicious APK packages.

One of the main payloads is CornFlake, a Go-based remote access trojan designed to maintain long-term access to Windows computers.

CornFlake can run remote commands, record keystrokes, monitor clipboard activity, capture screenshots, steal files, activate the microphone and webcam, extract browser passwords and cookies, steal Microsoft 365 session tokens, monitor connected USB devices, and collect detailed system information.

During installation, CornFlake displays a fake progress window while copying itself to the %AppData% folder. It disguises itself as a legitimate Windows component called Cloud Sync Service.

CornFlake uses several persistence methods

CornFlake can register itself as a Windows service to run automatically.

It can also create registry startup entries, scheduled tasks, and a watchdog process. The watchdog restores other persistence mechanisms when security teams remove one of them.

This approach makes the malware harder to remove completely from an infected device.

ChocoShell steals browser and Microsoft credentials

Microsoft also identified ChocoShell, an in-memory PowerShell credential stealer used during the campaign.

ChocoShell targets browser cookies, saved browser passwords, Microsoft 365 tokens, Azure AD tokens, and stored Wi-Fi credentials.

Because ChocoShell runs mainly in memory, it may leave fewer files for traditional security tools to detect.

Attackers manage victims through FruitStone

Microsoft discovered an exposed attacker control panel called FruitStone.

The panel allowed operators to manage infected systems, browse files, run PowerShell commands, collect screenshots, and review captured keystrokes.

Microsoft also found extensive comments inside the malware code. The comments suggest that the developers may have used AI tools while creating or modifying parts of the malware.

How travelers can protect their devices

Travelers and organizations should treat hotel and conference Wi-Fi as untrusted, even when the network appears legitimate.

Microsoft recommends the following precautions:

  • Use cellular data, a personal hotspot, or a managed corporate connection when possible.
  • Avoid installing browser updates, Windows updates, or security tools offered through captive portal pages.
  • Use passkeys or other phishing-resistant authentication methods.
  • Enable strong multifactor authentication for important accounts.
  • Disable Microsoft Entra device-code authentication when the organization does not need it.
  • Avoid entering corporate credentials when registering for guest Wi-Fi.
  • Contact an administrator when a captive portal asks users to run commands or download software.

In other security news, Microsoft’s bug bounty payouts reached a record $20 million.

More about the topics: malware, microsoft, Wi-Fi

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages