Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch
A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report:…
A Russia-affiliated hacking group known as Midnight Blizzard has infiltrated hotel and conference Wi-Fi networks across the globe, surreptitiously routing unsuspecting guests to fraudulent pages and bogus software updates designed to pilfer confidential information. According to Microsoft, the campaign, christened CaptiveCrunch, aims at business travelers in general, rather than a specific industry.
The US and UK governments attribute the cyber attacks to Russia's foreign intelligence agency, the SVR. Microsoft's technical assessment indicates breaches in multiple countries, though the exact number of affected establishments or individuals remains undisclosed. A prior investigation by security firm ReliaQuest, referenced by Microsoft, uncovered compromised captive portal gateways in various U.S. cities, alongside India and Saudi Arabia, primarily in sectors like financial services, professional services, legal, healthcare, energy, and retail.
The observed traffic originated from organizations spanning these industries, hinting at a broader target scope beyond specific sectors. Upon breach, the intruders deployed two primary tools: CornFlake, a Windows remote access trojan (RAT) written in Go that can record keystrokes, capture screenshots and webcam footage, eavesdrop on audio, and steal credentials and session tokens; and ChocoShell, an in-memory PowerShell infostealer that targets browser cookies, stored passwords, Microsoft 365 single sign-on (SSO) tokens, and Wi-Fi credentials.
Microsoft also suspects the attackers may be targeting Android devices with analogous prompts urging victims to download and install a malicious APK file.
Written by urgent.news from Slashdot's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.