
Hijacked Hotel Wi‑Fi Serves Fake Updates
Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…
Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login pages or fake update screens. The goal was to steal Microsoft 365 credentials and/or trick victims into installing espionage malware, especially targeting corporate travelers using captive portal Wi‑Fi.
This campaign targeted hotel and hospitality Wi-Fi networks that use captive portals, the login pages guests see before getting internet access. Attackers manipulated traffic on these compromised networks to redirect guests toward two types of fake pages. The first mimicked a Microsoft sign-in screen, aiming to capture Microsoft 365 usernames and passwords the moment a traveler tried to reconnect to email or cloud services. The second presented a fake browser or operating system update notice, using ClickFix-style prompts that persuaded victims to download and run malware themselves rather than being infected through a traditional exploit.
The attack succeeded by exploiting a moment of low suspicion. Travelers expect to see a login or verification screen after connecting to hotel Wi-Fi, so a fake Microsoft authentication page blended into that expected flow. Similarly, an update prompt appearing while browsing on unfamiliar network infrastructure did not immediately register as unusual to many users. Because the redirect happened at the network level rather than through a suspicious email or link, normal phishing instincts, like checking sender addresses, were less useful here.
Corporate travelers and executives using Microsoft 365 appear to be the primary targets, with observed impact across multiple U.S. cities as well as India and Saudi Arabia. The campaign may also be expanding beyond Windows: some fake update pages directed Android users to install a malicious application, suggesting attackers are broadening their reach across device types.
Training should reinforce that Microsoft 365 logins and system updates should never originate from a hotel Wi-Fi captive portal. Employees should be encouraged to close unexpected login pages and navigate to Microsoft services manually, and to rely only on their device's built-in update mechanism or company IT tools. High-risk travelers, including executives, may benefit from additional protections such as a VPN or a managed hotspot instead of relying on venue Wi-Fi. Organizations that operate their own captive portal networks, including conference centers, co-working spaces, universities, healthcare facilities, and event venues, should also monitor for signs of traffic manipulation or unexpected redirects, since this campaign shows that such infrastructure itself can become a vector for credential theft and malware delivery.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They compromised hotel and hospitality Wi-Fi networks that use captive portals and manipulated traffic to redirect guests to fake Microsoft login pages, capturing credentials as victims tried to authenticate.
Victims browsing on compromised hotel Wi-Fi were shown fake browser or operating system update pages that persuaded them to download and install malware themselves, a ClickFix-style social engineering approach.
Corporate travelers and executives using Microsoft 365 on hotel or other captive portal Wi-Fi appear to be the primary targets, though any organization operating captive portal networks, including airports, conference centers, and universities, could become a target.
No, some of the fake update pages included instructions directing Android users to download and install a malicious application, suggesting the operation may be expanding beyond Windows computers.
You connect to hotel Wi‑Fi, and boom, before anything loads, a Microsoft 365 login pops up. Microsoft and ReliaQuest saw this for real: hotel and airport Wi‑Fi hijacked, traffic manipulated, and guests silently redirected to fake Microsoft sign-in pages to steal M365 passwords or push malware updates. Here’s the trick: the login or 'required update' appears only after you join captive Wi‑Fi, as a redirect in your browser, not from your normal Microsoft app or your device’s update popup. That’s the tell. If a Microsoft 365 login or update page appears right after joining public Wi‑Fi, close it and go to office.com or your usual app yourself, never trust the page the Wi‑Fi forces on you.

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake…

Microsoft reported a real campaign where Russian-linked attackers tampered with hotel and conference Wi‑Fi “captive portals” to redirect travelers to…

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…