
Hijacked Hotel Wi‑Fi Serves Fake Updates
Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…
Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to attacker-controlled pages. Victims are pushed into fake Microsoft sign-ins (device code/OAuth phishing) or tricked into installing “browser/OS updates” that deliver malware and steal Microsoft 365 credentials and session tokens.
This campaign targets travelers connecting to Wi-Fi at hotels, conference centers, and other shared venues. Rather than relying on email, the attackers manipulate DNS and HTTP traffic served through captive portals, the login pages that appear when joining public Wi-Fi. This redirects victims through actor-controlled infrastructure before they ever reach a legitimate website.
From that position, the attackers ran two main plays. First, victims were shown fake browser or operating system update prompts, sometimes tied to automated connectivity checks. Some of these used ClickFix-style techniques, prompting users to manually run scripts or commands to "repair" their connection, which instead installed malware. Android users were sometimes told to download and install an APK file directly from the captive portal page.
Second, the attackers used adversary-in-the-middle phishing with doppelganger domains that closely mimic Microsoft's online services. These pages abused the device code and OAuth authentication flows in Microsoft Entra ID, tricking users into approving what looked like a normal sign-in but actually let the attacker register a device and access Microsoft 365 data.
The attack succeeds because it exploits a moment when users have low suspicion: connecting to Wi-Fi in an unfamiliar location and just wanting to get online. Captive portals and connectivity checks are a normal part of using public networks, so a prompt to "update" or "verify" blends into an expected experience. The use of device code authentication is especially effective because many users are unfamiliar with what a legitimate device code flow looks like, making it hard to distinguish from a real Microsoft prompt.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers manipulate DNS and HTTP traffic on hospitality networks served by captive portals to redirect travelers through actor-controlled infrastructure, where they are shown fake update prompts or phishing sign-in pages.
After joining venue Wi-Fi, users see a prompt saying their browser or operating system needs an update to continue connecting. Following the instructions, which sometimes involve running commands via ClickFix techniques, installs malware instead.
The campaign uses lookalike doppelganger domains that mimic Microsoft online services and abuses the device code authentication flow in Microsoft Entra ID, allowing attackers to register devices and access Microsoft 365 data without needing the user's password directly.
Corporate travelers are the primary target, including executives, sales and field staff, finance, and IT administrators who connect to hotel or conference center Wi-Fi while working remotely.
You join hotel Wi‑Fi, and before you even open a site, a page pops up: “Your browser needs an update to continue connecting.” Microsoft calls this the CaptiveCrunch campaign. Attackers tamper with captive portal traffic at hotels and conference centers, pushing fake browser or OS updates that are actually malware stealing your Microsoft 365 credentials and session tokens. Or you get bounced to a Microsoft sign-in that looks normal, but the address bar shows a doppelganger domain, and it asks for a device code you never started. That’s CaptiveCrunch abusing Microsoft Entra ID device code auth to hijack your session. Aha moment: captive portals are untrusted. If Wi‑Fi forces an “update” download or surprise Microsoft sign-in, stop, close the tab, and use your phone’s hotspot or VPN instead.

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake…

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login…

Microsoft reported a real campaign where Russian-linked attackers tampered with hotel and conference Wi‑Fi “captive portals” to redirect travelers to…

Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…