Forgot your password?
typodupeerror
Privacy Wireless Networking Security

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch (itnews.com.au) 31

A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals.

A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector.

[...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

Comments Filter:
  • by Anonymous Coward
    Use your phone instead.
    • Re: (Score:2, Insightful)

      by Anonymous Coward

      No I'll just decline when the hotel wifi asks for my SSN and date of birth

      • I bring a 4 meter cable since sometimes WiFi performance poor especially affecting connections via VPNs. Usually there is a network cable into TV , if no router port. Need a cable extension adapter. Does not fully avoid a compromised connection if hotel system but beats weak wifi. There are other precautions such as no admin privileges on user accounts etc
      • by PPH ( 736903 )

        Just use 078-05-1120. It's the number on the SS card that came with my new wallet.

        Note that is not illegal to provide an incorrect SSN to parties other than the government or those with a duty to report financial transactions.

        If they ask for a birthdate, reply like Crocodile Dundee: "In the summer."

        • Re: (Score:2, Informative)

          by Anonymous Coward

          The surveillance state has conscripted hotels to verify identity. They'll tell you its for fraud prevention, or because local laws require it. But the vast majority of hotels in the US (and probably Canada) require a photo id. So at the very least they've recorded your driver's license number and full name and DOB. It's automatic if they have a DL scanner (either barcode or image-based software)

          • I did some googling and came up with this:

            - In the USA and in Canada, hotels are required by law to keep records of their guests' identities;
            - in Canada, law enforcement may obtain this information with a warrant;
            - in the USA, a warrant may not be required, depending on jurisdiction.

            Other countries generally have policies that resemble either of the above.

            • by PPH ( 736903 )

              In the USA and in Canada, hotels are required by law to keep records of their guests' identities;

              Don't know about Canada. But in the USA, blocks of hotel rooms are sometimes reserved to house undocumented immigrants. Who, by definition, can't establish an identity.

              • Don't know about Canada. But in the USA, blocks of hotel rooms are sometimes reserved to house undocumented immigrants. Who, by definition, can't establish an identity.

                "By definition?" No, I don't think that's the case. Undocumented immigrants lack immigration documents, not necessarily identity documents.

                And presumably undocumented immigrants would need to present whatever identification documents they have when they check into a hotel, whether the tab is on Uncle Sam or not.

                • by PPH ( 736903 )

                  If you can establish a minimum level of documentation an immigrant must have in order to qualify for assistance or other services, I'd be more than happy to pass that on to our state.

                  Anecdote: I was stuck in line at the grocery store behind a lady (quite attractive) attempting to buy a moneygram. She presented a piece of paper (I'm guessing) with the amount and recipient. But when prompted for ID, all she could say was "No se. No se." After some time, she got her moneygram and moved on. When I left, I pass

        • by pz ( 113803 )

          If they ask for a birthdate, reply like Crocodile Dundee: "In the summer."

          For services that have no damned business knowing my real birthdate, I always use the start of the Unix epoch: 1/1/1970.

          It has two advantages; (1) most calendar picker widgets default to January 1, so it's fewer clicks, and (2), for me at least, it is close enough to being true that no one would ever challenge it, even in person.

    • In some cities like D.C., New York, Paris the time between the time you join the hotel network and are attacked is less than 5 minutes. It is fun to travel with WireShark and watch this, but not with a computer you care about. So yes, use your cell phone, not the hotel network.

      It is more common than people realize that these BusyBox based cheap commodity network servers suffer a regression where test code is accidentally included in a given release. When that happens, the devices are quickly owned. Tha
  • DEFCON (Score:5, Funny)

    by backslashdot ( 95548 ) on Tuesday August 04, 2026 @10:24AM (#66272120)

    I'm not too worried, as hotels should have these patched within two weeks. Just thank God there's no hacker conference this weekend in a city like Las Vegas, which has the most hotel rooms in America.

  • If so how are bad packages installed ? Debian keeps keys in /etc/apt/trusted.gpg.d/ [debian.org] and has done so since 2005.

  • I one hostel in Stockholm the router used default password so you could login into router and see what happened in the wireless network.
  • by King_TJ ( 85913 ) on Tuesday August 04, 2026 @03:03PM (#66272640) Journal

    I don't do a lot of traveling, but I remember when I last worked at a job that involved some travel? The ongoing "wisdom" was a realization that the cheaper hotels had the most usable/reliable wifi. The expensive ones tended to use Internet as a service to upsell, with annoying portals trying to bill you a daily rate and generally interfering with your applications. (They might, for example, lock down just about all ports except 80 and 443, meaning you couldn't get software updates to complete or connect a VPN, or ....)

    The basic chains, by contrast, all seemed to used "canned" wifi setups sold to them by third party vendors, and as long as you got a decent signal in your room, you were good.

    In any case, I never trusted a hotel wifi to be super-secure. Heck, I remember on a Vegas trip one time, they had it set up so wifi was capped at a slow rate unless you paid a premium. I was curious about a wired jack I found behind the bed and plugged into it. Turns out, it gave me a full gigabit network connection and bypassed their sign-in portal and everything. They seemed to just not realize or expect guests would still carry ethernet cables with them and try to use a wired connection.

The best things in life go on sale sooner or later.

Working...