Microsoft warns travellers: Hotel Wi-Fi can expose passwords, audio and video
Microsoft has issued a warning for travelers about potential cyberattacks targeting hotel Wi-Fi networks. The CaptiveCrunch campaign, linked to group Storm-2945, leads users to fraudulent portals. Victims might unconsciously download harmful files or disclose sensitive information. These threats are focused on compromising Microsoft 365 accounts and gaining unauthorized network access. For…
Microsoft has cautioned travelers about the dangers of using hotel Wi-Fi networks, which can potentially expose passwords, audio, and video data. The company's Threat Intelligence team has uncovered a sophisticated cyberattack campaign dubbed 'CaptiveCrunch' that has been active since at least May. This attack, attributed to the Russian hacking group Storm-2945, is believed to belong to the Midnight Blizzard hacking group (known as APT29 or Cozy Bear).
The hackers compromise hotel Wi-Fi infrastructure, redirecting unsuspecting guests through fake portals and malicious pop-ups. Upon connecting, victims are tricked into downloading malware or entering sensitive credentials, believing they are completing routine security checks. Once malware is installed on a device, attackers gain extensive control, capturing keystrokes, recording audio and video, taking screenshots, stealing browser cookies and passwords, and remotely operating the infected device.
Microsoft warns of several fake pop-up windows that may appear on compromised networks, including Windows Update, Windows Security virus scans, DirectX End-User Runtime Web Installer, Microsoft Visual C++ Redistributable installers, disk optimization utilities, and various browser update prompts. To stay safe, travelers are advised to use cellular hotspots, avoid public or hotel Wi-Fi networks, ignore unexpected pop-ups, limit data sharing, and ensure their company follows strict data protection measures when logging onto guest networks.
Written by urgent.news from Times of India's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.