
Captive Portal Trick Hits Travelers With Fake Updates
Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to…
Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake browser/OS update prompts (and sometimes “paste-and-run” instructions) to install malware, and later were pushed into Microsoft device-code sign-in flows to steal corporate account access.
This campaign hijacked captive portals, the login pages that appear when a device joins a new Wi-Fi network, at hotels and conference venues. Instead of waiting for a traveler to open a browser and visit a site, the attackers answered the automated connectivity checks that operating systems and browsers send the moment a device joins a network. Those checks returned pages offering fake browser or system updates, making the lure appear at the earliest possible moment, before the victim had a chance to browse anywhere on their own.
Some of these hijacked landing pages went further, using ClickFix-style tactics: a fake "verification failed" message paired with paste-and-run instructions that asked the victim to manually copy and execute commands to "fix" their connection. Others served an Android APK directly. Later in the campaign, from July 16 onward, some pages redirected victims into Microsoft's device code authentication flow, instructing them to type an attacker-supplied code into a genuine Microsoft sign-in page to complete the corporate account takeover.
The attack exploited the routine, largely invisible moment of joining Wi-Fi. Because the fake update prompts arrived through the automatic connectivity check rather than a webpage the user chose to visit, the request felt like a normal part of getting online rather than a suspicious pop-up. The device code technique is not new, but embedding it inside a captive portal made the request feel like a legitimate step in accessing the network rather than an unusual account sign-in request.
Travelers, executives, sales staff, consultants, and anyone using hotel, conference, or airport Wi-Fi should treat these networks as untrustworthy by default. Never install software offered through a captive portal, and never enter a device code on a sign-in page unless you initiated that authentication request yourself. If a Wi-Fi login page asks for troubleshooting steps involving pasted commands, stop and report it to IT or security rather than following the instructions.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromised captive portals on hotel and conference Wi-Fi networks and answered the automatic connectivity checks that devices send when joining a new network, returning pages that offered fake browser or operating system updates instead of a normal login page.
From July 16, some captive portal pages redirected victims into Microsoft's device code authentication flow and told them to enter an attacker-supplied code on a genuine Microsoft sign-in page, which let attackers gain access to the account.
Some hijacked landing pages showed a fake verification failure message and instructed victims to copy and paste commands to fix their connection, a technique known as ClickFix that tricks users into running malicious commands themselves.
Treat hotel, conference, and airport wireless networks as untrustworthy, never install software offered through a captive portal, and never enter a device code on a Microsoft sign-in page that you did not initiate yourself.
You join hotel Wi‑Fi, and before you even browse, a page pops up: “Browser update required to get online.” That’s CaptiveCrunch. Storm‑2945 hijacks hotel and conference captive portals and answers your laptop’s automatic connectivity check with a fake browser or OS update that installs espionage malware. Some pages even show a fake verification failure with “paste these commands to fix Wi‑Fi,” or push you into a real Microsoft device‑code sign‑in and tell you which code to enter to grab your corporate account. If hotel or conference Wi‑Fi ever tells you to install an update or paste commands to get online, stop, don’t do it, and report it to IT immediately.

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to…

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login…

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…