Category
World

Russian State Hackers Target Hotel Wi-Fi Networks Worldwide, Microsoft Warns

2 min read
Google logo Prefer U24 Media on Google
Authors
A person types with gloved hands on an illuminated laptop keyboard. Illustrative image. (Source: Getty Images)
A person types with gloved hands on an illuminated laptop keyboard. Illustrative image. (Source: Getty Images)

Russian state-sponsored hackers have launched a global cyber espionage campaign targeting public Wi-Fi networks at hotels and conference centers to breach the devices of corporate executives and government travelers, Microsoft Threat Intelligence reported on August 5.

The campaign, dubbed CaptiveCrunch, is being conducted by a group tracked as Storm-2945, which Microsoft assesses to be an operational unit of Midnight Blizzard—the Russian state threat actor previously linked by US and UK intelligence to Russia’s Foreign Intelligence Service (SVR).

We bring you stories from the ground. Your support keeps our team in the field.

DONATE NOW

Microsoft reported that the group has leveraged artificial intelligence tools to accelerate its operations, deploying sophisticated phishing flows and malicious software to intercept traffic from business travelers connecting to hotel guest networks.

By compromising the management systems behind hotel Wi-Fi registration pages, the Russian intelligence unit manipulates internet traffic and redirects guests to malicious infrastructure disguised as legitimate browser updates or system prompts.

Security researchers at ReliaQuest, cited by Microsoft, confirmed that these operations specifically target high-value corporate travelers across shared venues to capture login tokens and gain unauthorized access to corporate Microsoft 365 environments.

Midnight Blizzard has a documented history of conducting high-priority intelligence collection to support Kremlin foreign policy goals, targeting government agencies, diplomatic missions, and IT service providers across the United States and Europe. Microsoft noted that incorporating hotel Wi-Fi traffic manipulation into their arsenal allows Russian operatives to bypass conventional perimeter defenses by striking executives while they are away from corporate headquarters.

To counter the threat, Microsoft advised organizations to restrict employee reliance on unverified public Wi-Fi networks, utilize enterprise-managed mobile hotspots or travel routers, and enforce strict identity controls to prevent unauthorized access to corporate cloud resources.

The wave of hotel Wi-Fi attacks coincides with an expanding effort by Russian intelligence to breach Western critical infrastructure. A joint intelligence advisory had previously revealed that Russian state hackers ran a yearlong campaign targeting US nuclear researchers and NATO defense contractors, using zero-click email exploits to compromise accounts without victim interaction.

British Security Minister Dan Jarvis warned that Russia routinely tests these emerging cyber methods against Ukrainian targets before shifting them against Western allies.

Truth is Under Attack
Logo
Truth is Under Attack
We report the war as it unfolds directly from the people and places most affected by it. Your support helps us bring these stories to the world.
See all

Never miss a frontline update

Make UNITED24 Media a preferred source on Google and get our exclusive reporting and military analysis from inside Ukraine.