Urgent.News

What's breaking now, across thousands of outlets.

Culture

Hackers linked to Russia’s Foreign Intelligence Service intercepted hotel Wi-Fi worldwide to steal officials’ and executives’ data

Russian state-linked hackers have been breaking into hotel Wi-Fi networks around the world to steal data from corporate employees on business trips, according to a report by Microsoft Threat Intelligence released on July 31. Microsoft said it has been monitoring the attacks since early May 2026, while operations by the Storm-2945 group, which is linked to another group known as Midnight Blizzard,…

Hackers linked to Russia’s Foreign Intelligence Service intercepted hotel Wi-Fi worldwide to steal officials’ and executives’ data

Russian state-sponsored hackers affiliated with the Foreign Intelligence Service (SVR) have been infiltrating hotel Wi-Fi networks globally to pilfer sensitive data from corporate employees and executives, as reported by Microsoft Threat Intelligence on July 31. The attacks, orchestrated by the Storm-2945 group and linked to Midnight Blizzard, commenced in February and involved intercepting DNS and HTTP traffic on hotel Wi-Fi networks.

By masquerading as software updates, the hackers delivered malware to unsuspecting victims and employed ClickFix techniques to trick users into downloading malicious scripts. Several tools were utilized in the campaign, including CornFlake, a remote-access Trojan written in Go, capable of recording keystrokes, taking screenshots, and stealing passwords and session tokens.

Another tool, the PowerShell-based ChocoShell infostealer, focused on capturing cookies, saved passwords, Microsoft 365 tokens, and Wi-Fi passwords. Infected devices were controlled via a web panel called FruitStone, and AI played a significant role in executing the operations. The SVR targets governments, diplomatic missions, NGOs, and technology firms in the U.S. and Europe, with the primary objective of intelligence gathering to support Russian foreign policy interests.

Microsoft advises caution when using hotel, conference, and airport Wi-Fi, recommending the use of mobile data where possible and avoiding updates prompted by pop-up windows or during Wi-Fi logins.

Written by urgent.news from The Insider's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theins.press →

More in Culture

More from Wednesday 5 August →