
Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing
Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled…
Microsoft and ReliaQuest report a real campaign where attackers tampered with public Wi‑Fi captive portal networks (hotels/conference venues) to redirect users to attacker-controlled pages. The goal was to steal Microsoft 365 credentials (and sometimes deliver malware) by using adversary-in-the-middle tactics, fake “browser update” lures, and device-code sign-in prompts that look legitimate to travelers.
This campaign targeted the moment employees are most vulnerable: connecting to Wi-Fi in an unfamiliar hotel, conference center, or shared venue. Attackers manipulated DNS and HTTP traffic within captive portal networks, redirecting users away from the legitimate Wi-Fi login page toward attacker-controlled infrastructure. From there, the operation used adversary-in-the-middle techniques to intercept Microsoft 365 credentials as victims tried to sign in.
The redirected pages presented two main lures. One claimed the user's browser needed an update to get online, which actually delivered a Golang-based Windows remote access trojan, or tried to entice Android users into installing a malicious APK using ClickFix-style prompts. The other pushed a Microsoft device code authentication flow, asking victims to enter a code into a legitimate-looking Microsoft sign-in page, which in reality authorized the attacker's own session.
The attack exploited trust in an everyday routine. Travelers expect to click through a Wi-Fi login page before getting online, so a prompt to "update your browser" or authenticate a session did not feel unusual. Embedding the phishing inside the captive portal itself, rather than sending a separate suspicious email, increased the likelihood that users would perceive the requests as a normal part of connecting to the network rather than as an attack.
Employees who travel, along with executives, sales, consultants, finance, legal, and healthcare staff, should treat public Wi-Fi portals as untrusted by default. Corporate credentials should never be entered into a captive portal page, and no browser update or app install should ever be accepted from one. If a device code prompt appears unexpectedly, the safest move is to stop and report it rather than complete the sign-in, since it may hand an attacker control of an active session. Building this habit into travel security awareness reduces the chance that a routine hotel or conference Wi-Fi connection turns into a credential theft incident.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They manipulated DNS and HTTP traffic from captive portal networks at hotels, conference centers, and shared venues to redirect users to attacker-controlled pages, then used adversary-in-the-middle techniques to intercept Microsoft 365 credentials.
Some landing pages directed victims to Microsoft's device code authentication flow, instructing them to enter a code into a real Microsoft sign-in page, which authorized the attacker's session instead of the user's.
The campaign served Golang-based Windows remote access trojans disguised as browser updates and used ClickFix-style prompts to get Android users to install a malicious APK.
Traveling employees, executives, sales staff, consultants, and anyone using Microsoft 365 on public Wi-Fi at hotels, conference centers, or shared venues are the primary targets.
You connect to hotel Wi‑Fi, and the login page says, “To continue, update your browser.” That’s the trap. Microsoft calls this CaptiveCrunch. Storm‑2945 hacked hotel and conference Wi‑Fi DNS so the portal can push fake browser updates and even Android APKs that are actually malware. Even sneakier: some portals show a Microsoft device code screen, “Enter this code at Microsoft to connect.” If you do it, you’re authenticating their Microsoft 365 session, not yours. Here’s the rule: if public Wi‑Fi ever asks you to install a browser update, APK, or enter a Microsoft device code you didn’t start, disconnect and report it to security immediately.

Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled…

Microsoft says Russian SVR operators (Storm-2945/Midnight Blizzard) are compromising public Wi‑Fi captive portals in hotels and conference venues to redirect…

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake…

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login…

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…