Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware
Russian criminals are targeting hotel Wi-Fi networks with captive portals and using them to deploy infostealers.
Microsoft experts caution travelers about the potential for hackers to hijack hotel Wi-Fi networks and infect devices with malware. Russian state-sponsored actors, identified as Midnight Blizzard or APT29, have been targeting captive portal equipment - the hardware and software that manages the login page before users can access public Wi-Fi.
When users attempt to connect to these networks, they may be redirected to fraudulent Microsoft 365 login pages or bogus update pages, which can lead to the spread of two types of malware: CornFlake and CocoShell.
CornFlake operates as an information stealer, capable of capturing keystrokes, clipboard data, executing remote shell commands, capturing screenshots, accessing webcams and microphones, stealing browser credentials and cookies, and exfiltrating files. In contrast, CocoShell is an in-memory PowerShell credential stealer that targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.
The researchers from Microsoft did not specify how the attackers gain control over the captive portal equipment, but stressed the importance of travelers being vigilant when connecting to public Wi-Fi networks in hotels and conference centers.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.