Russian Hackers Hijack Hotel Wi-Fi to Deploy Surveillance Malware

Russian Hackers Hijack Hotel Wi-Fi to Deploy Surveillance Malware

Travelers and conference attendees worldwide are facing a newly disclosed cybersecurity threat that turns routine hotel and venue Wi-Fi connections into delivery systems for sophisticated surveillance malware. Microsoft has revealed that Russian foreign intelligence operatives are actively compromising public Wi-Fi captive portal networks to infect devices with powerful malware strains capable of keylogging, audio-visual surveillance, and credential theft.

The CaptiveCrunch Campaign: What We Know

Microsoft’s Threat Intelligence team attributed the operation, dubbed CaptiveCrunch, to Storm-2945, a subdivision of the SVR’s notorious Midnight Blizzard group, also known as Nobelium. The campaign specifically targets users connecting to public Wi-Fi networks at hotels, conference centers, and other hospitality venues around the globe.

The broader AI-assisted operation dates back to February 2026, with observable traffic manipulation beginning in early May. Microsoft has not yet fully determined how the attackers initially compromise the captive portal networks, but once they gain control of the network layer, the consequences for connected users are severe.

How the Attack Works

The attack chain follows a methodical and dangerous sequence:

  • Attackers compromise the captive portal network at a hospitality venue
  • They manipulate DNS and HTTP traffic to reroute users through attacker-controlled infrastructure
  • The crew abuses operating system connectivity checks to trigger malicious prompts and redirects
  • This establishes an adversary-in-the-middle (AitM) position on the network
  • Users are presented with ClickFix-style prompts disguised as legitimate OS updates, driver repairs, or web verification failures
  • Users who follow the fake instructions unknowingly install malware on their devices

The ClickFix method has become increasingly prevalent in recent malware campaigns. By presenting what appears to be a routine system update or verification step, attackers exploit users’ trust in standard technical processes. When connected to a compromised hotel network, these prompts carry an additional layer of false legitimacy because they appear during the expected captive portal authentication flow.

Inside the Malware: CornFlake and ChocoShell

Two malware strains form the backbone of the CaptiveCrunch campaign. The first, CornFlake, is described by Microsoft as a full-featured Windows remote access trojan (RAT) written in the Go programming language. It serves as the SVR’s primary persistent implant in these hospitality network attacks.

CornFlake initially presents victims with a convincing fake Windows update progress window, masking the installation process behind a familiar interface. Once installed, the malware grants attackers an extensive suite of surveillance and data theft capabilities:

  • Keylogging — captures every keystroke entered on the infected device
  • Clipboard monitoring — intercepts copied text and data
  • Screenshot capture — takes periodic images of the user’s screen
  • Audio surveillance — activates microphones to record conversations
  • Video surveillance — activates cameras to record the user and environment
  • Browser credential theft — extracts saved passwords and login data
  • File exfiltration — silently copies files from the victim’s device
  • USB drive monitoring — tracks external storage devices connected to the system
  • Security posture sweep — assesses installed security tools and defenses
  • Remote shell — provides full interactive command-line access to the attacker

What makes CornFlake particularly dangerous is its modular architecture. The malware exposes a localhost HTTP API server that allows it to function as a platform for delivering additional payloads on demand. Chief among these is ChocoShell, a PowerShell-based infostealer that is delivered and executed entirely in memory, making it significantly harder to detect with traditional endpoint security tools.

ChocoShell is designed to rapidly extract the most operationally valuable data from a compromised device: browser session cookies, saved passwords, single sign-on (SSO) tokens, and Wi-Fi credentials. As Microsoft explained, CornFlake provides the persistent foothold while ChocoShell extracts the credentials that give attackers access to the victim’s broader cloud environment.

Beyond Malware: Device Code Phishing

The CaptiveCrunch campaign extends beyond malware delivery. Microsoft disclosed that a portion of the SVR’s activity is devoted to device code phishing, a technique that exploits a legitimate OAuth authentication flow typically reserved for devices that cannot easily open web browsers, such as smart TVs and IoT devices.

In this attack variant, users redirected to attacker-controlled landing pages are instructed to enter a device code on a legitimate Microsoft authentication page. The code was originally generated for the attacker, but when the victim enters it and selects their account, they unwittingly complete an authentication flow that grants the attacker a valid OAuth token for the victim’s Microsoft 365 account.

This token provides access to cloud data until it expires or is revoked. Device code phishing is particularly effective because it can bypass multi-factor authentication (MFA), and when combined with the adversary-in-the-middle position achieved through captive portal compromise, users are far more likely to perceive the authentication request as legitimate.

Who Is at Risk?

The primary targets are Windows users, but Microsoft has also observed ClickFix prompts tailored to Android devices, encouraging users to download and install malicious APK files. The hospitality sector is particularly vulnerable because captive portal networks are inherently trusted by users who expect to authenticate before gaining internet access.

Travelers attending conferences, staying at hotels, or using shared venue Wi-Fi are the primary audience at risk. However, the implications extend to their employers: a compromised device brought back to a corporate network can serve as a beachhead for further intrusion into enterprise systems and cloud environments.

How to Protect Yourself

Microsoft’s guidance and cybersecurity best practices suggest several key protective measures:

  • Avoid public Wi-Fi for sensitive activities — Use personal hotspots or satellite internet connections instead of shared hospitality networks whenever possible
  • Never install updates over public Wi-Fi — Legitimate operating system updates are never delivered through captive portal prompts. Treat any such prompt as suspicious
  • Recognize ClickFix attacks — Educate yourself and your team about what fake update prompts and verification failures look like
  • Use a VPN — A reputable virtual private network encrypts your traffic and prevents DNS and HTTP manipulation by network-level attackers
  • Disable device code authentication — Organizations should disable the device code authentication flow wherever possible to prevent employees from inadvertently surrendering cloud access
  • Adopt passwordless authentication — Passwordless methods can thwart many phishing techniques, though device code phishing may still bypass even passkeys in certain scenarios
  • Monitor for compromise — Organizations should watch for signs of CornFlake or ChocoShell activity, including unexpected network connections to localhost HTTP servers and unusual PowerShell execution patterns

The Bigger Picture

The CaptiveCrunch campaign represents a significant evolution in how nation-state actors are weaponizing public infrastructure. By compromising the Wi-Fi networks that travelers have come to expect as a standard amenity, the SVR has turned a routine convenience into a targeted attack surface.

This campaign also highlights the growing sophistication of ClickFix-style social engineering, where attackers exploit users’ familiarity with technical troubleshooting processes. When combined with adversary-in-the-middle positioning and device code phishing, the attack chain becomes remarkably difficult for even security-conscious users to detect.

For the hospitality sector, the implications are serious. Hotels and conference venues must treat their captive portal infrastructure as critical security assets, implementing network segmentation, regular security audits, and anomaly detection to identify when their systems have been compromised.

As state-sponsored threat actors continue to refine their techniques, the line between digital and physical security grows increasingly blurred. A hotel Wi-Fi network is no longer just a convenience — it is a potential battlefield, and every connected device is a potential casualty.


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading