Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch (itnews.com.au) 31
A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals.
A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector.
[...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.
A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector.
[...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.
Re: (Score:1)
The reason we don't have Hillary's emails is that nobody is asking for them, because nobody is expecting anything interesting in them. Even Republicans don't care about it. There's a national consensus: it's boring.
OTOH the reason we don't have the Epstein files is that Donald Trump is a pedophile and the files support that fact, so he ordered the AG to break the law and keep the files unreleased.
Don't ever use hotel WiFi (Score:1)
Re: (Score:2, Insightful)
No I'll just decline when the hotel wifi asks for my SSN and date of birth
Re: Don't ever use hotel WiFi (Score:2)
Re: (Score:3)
Just use 078-05-1120. It's the number on the SS card that came with my new wallet.
Note that is not illegal to provide an incorrect SSN to parties other than the government or those with a duty to report financial transactions.
If they ask for a birthdate, reply like Crocodile Dundee: "In the summer."
Re: (Score:2, Informative)
The surveillance state has conscripted hotels to verify identity. They'll tell you its for fraud prevention, or because local laws require it. But the vast majority of hotels in the US (and probably Canada) require a photo id. So at the very least they've recorded your driver's license number and full name and DOB. It's automatic if they have a DL scanner (either barcode or image-based software)
Re: (Score:3)
I did some googling and came up with this:
- In the USA and in Canada, hotels are required by law to keep records of their guests' identities;
- in Canada, law enforcement may obtain this information with a warrant;
- in the USA, a warrant may not be required, depending on jurisdiction.
Other countries generally have policies that resemble either of the above.
Re: (Score:3)
In the USA and in Canada, hotels are required by law to keep records of their guests' identities;
Don't know about Canada. But in the USA, blocks of hotel rooms are sometimes reserved to house undocumented immigrants. Who, by definition, can't establish an identity.
Re: (Score:1)
Don't know about Canada. But in the USA, blocks of hotel rooms are sometimes reserved to house undocumented immigrants. Who, by definition, can't establish an identity.
"By definition?" No, I don't think that's the case. Undocumented immigrants lack immigration documents, not necessarily identity documents.
And presumably undocumented immigrants would need to present whatever identification documents they have when they check into a hotel, whether the tab is on Uncle Sam or not.
Re: (Score:3)
If you can establish a minimum level of documentation an immigrant must have in order to qualify for assistance or other services, I'd be more than happy to pass that on to our state.
Anecdote: I was stuck in line at the grocery store behind a lady (quite attractive) attempting to buy a moneygram. She presented a piece of paper (I'm guessing) with the amount and recipient. But when prompted for ID, all she could say was "No se. No se." After some time, she got her moneygram and moved on. When I left, I pass
Re: (Score:3)
But I'm a brown person and an immigrant.
scared of getting your ass kicked?
No, but it seems that you are. Frightened by anyone that politicians label as "vulnerable groups" and willing to allow them to break the law rather than call them out on it.
Re: (Score:2)
If they ask for a birthdate, reply like Crocodile Dundee: "In the summer."
For services that have no damned business knowing my real birthdate, I always use the start of the Unix epoch: 1/1/1970.
It has two advantages; (1) most calendar picker widgets default to January 1, so it's fewer clicks, and (2), for me at least, it is close enough to being true that no one would ever challenge it, even in person.
Re: (Score:3)
It is more common than people realize that these BusyBox based cheap commodity network servers suffer a regression where test code is accidentally included in a given release. When that happens, the devices are quickly owned. Tha
DEFCON (Score:5, Funny)
I'm not too worried, as hotels should have these patched within two weeks. Just thank God there's no hacker conference this weekend in a city like Las Vegas, which has the most hotel rooms in America.
Re: (Score:1)
Countries spy on each other even during times of peace.
Did you have a point?
Re: (Score:2)
When we are at war with Russia, neither side is going to be uncertain of that fact. This isn't war, it's just a little light foreplay between nuclear armed super powers.
Re: (Score:2)
Yeah, I get a real bottom vibe from Trump. Not even a power bottom.
Does Microsoft not sign packages ? (Score:3)
If so how are bad packages installed ? Debian keeps keys in /etc/apt/trusted.gpg.d/ [debian.org] and has done so since 2005.
WIFI is insecure (Score:1)
Don't most hotels outsource their wifi? (Score:3)
I don't do a lot of traveling, but I remember when I last worked at a job that involved some travel? The ongoing "wisdom" was a realization that the cheaper hotels had the most usable/reliable wifi. The expensive ones tended to use Internet as a service to upsell, with annoying portals trying to bill you a daily rate and generally interfering with your applications. (They might, for example, lock down just about all ports except 80 and 443, meaning you couldn't get software updates to complete or connect a VPN, or ....)
The basic chains, by contrast, all seemed to used "canned" wifi setups sold to them by third party vendors, and as long as you got a decent signal in your room, you were good.
In any case, I never trusted a hotel wifi to be super-secure. Heck, I remember on a Vegas trip one time, they had it set up so wifi was capped at a slow rate unless you paid a premium. I was curious about a wired jack I found behind the bed and plugged into it. Turns out, it gave me a full gigabit network connection and bypassed their sign-in portal and everything. They seemed to just not realize or expect guests would still carry ethernet cables with them and try to use a wired connection.
Re: (Score:2)
Yes, and that's exactly how the hackers got into the systems. They didn't have to hack every hotel, just those outsourced service providers that the hotels all use.
https://www.infosecurity-magaz... [infosecuri...gazine.com].