
Microsoft has issued an urgent warning to travellers about a sophisticated hacking campaign targeting hotel Wi-Fi networks globally. The operation, known as “CaptiveCrunch,” is attributed to Storm-2945, a sub-cluster of the Russian state-backed hacking group Midnight Blizzard, which is associated with Russia’s Foreign Intelligence Service (SVR).
Hackers have been exploiting captive portal networks at hotels, conference centers, and other hospitality businesses since early May. Users who connect are led to malicious Microsoft 365 websites or are asked to download malicious software disguised as legitimate updates. This malware is called CornFlake, and is capable of stealing keystrokes, screenshots, audio, video, and browser cookies and passwords.
The hackers also use “ClickFix” techniques, showcasing fake Windows Update screens, virus scans, or browser update prompts to trick users into downloading malware.
Additionally, the hackers use the “ClickFix” approach by showing fake Windows Update prompts, virus check alerts, or browser update alerts. This makes the user download the malware. In other instances, victims are forced to input device codes on the legitimate authentication page of Microsoft, which is called device code phishing, giving the attackers access to the business accounts.
It is advisable for travelers to use a private connection such as mobile hot spots instead of public Wi-Fi if possible. It is not advisable for users to download software updates or security utilities provided through the captive portals.
2026-08-04 18:47:00










