Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

TechSpot · High sophistication
Last updated August 4, 2026

Microsoft reports a Russian state-backed operation that compromises hotel and conference Wi‑Fi “captive portals” to redirect travelers to fake Microsoft 365 sign-in pages or fake update prompts that install malware. One method abuses Microsoft’s device-code login flow so victims unknowingly approve the attacker’s session, potentially bypassing MFA. The campaign appears aimed at corporate travelers across many industries rather than a single sector.

Key findings

  • Microsoft says a Russian state-backed campaign compromises hotel/conference Wi‑Fi captive portals and redirects users to attacker-controlled content.
  • Victims are shown convincing Microsoft 365 login pages and, in one variation, are tricked into completing device-code authentication that authorizes the attacker’s session.
  • Other victims see fake Windows/browser/security/network repair prompts designed to get them to install malware.
  • Tools described include CornFlake (remote access trojan) and ChocoShell (PowerShell infostealer focused on browser and Microsoft 365 token theft).
  • The campaign appears to target corporate travelers broadly (financial, legal, healthcare, energy, retail, and professional services mentioned).

Who’s being targeted

  • Commonly targeted roles: All employees who travel, Executives, Finance, Legal, Sales, Consultants, IT / Helpdesk.
  • Affected industries: Hospitality (hotels, conferences, captive-portal Wi‑Fi operators), Financial services, Legal services, Healthcare, Energy, Retail, Professional services.
  • Attack channels: website.
  • Impersonated: Microsoft 365 sign-in, Microsoft device sign-in (device-code authentication), Windows Update / Microsoft Defender / browser update / DirectX / network repair tool.

Awareness takeaways

  • Treat hotel, conference, and airport Wi‑Fi as untrusted; prefer a personal hotspot or private connection.
  • Never install software, updates, certificates, or ‘network repair’ tools offered by a captive portal.
  • Reject unexpected Microsoft device-code sign-in requests; only approve sign-ins you personally initiated.
  • Where possible, use phishing-resistant sign-in methods (passkeys / phishing-resistant MFA) and reduce unnecessary device-code authentication in the organization.

Red flags to watch for

  • Login prompt appears immediately after joining guest Wi‑Fi/captive portal
  • Unexpected Microsoft 365 sign-in request while merely trying to access Wi‑Fi
  • Captive portal behavior seems unusual (extra redirects / repeated prompts)
  • Unexpected device-code prompt when you did not initiate a sign-in
  • A code is provided to you that you didn’t request
  • The request happens while connecting to hotel/conference Wi‑Fi
  • Updates offered through a Wi‑Fi login/terms page instead of the normal OS update process
  • Pressure to install a certificate/tool to get internet access
  • Update prompts that appear only on a specific Wi‑Fi network
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You join hotel Wi‑Fi, click past the terms page… and suddenly you’re staring at a Microsoft 365 login screen. Microsoft says a Russian state-backed group is hijacking hotel and conference captive portals, silently redirecting you to fake M365 logins or a real Microsoft device-code page where you enter their code and unknowingly approve their session. Red flags: the M365 login pops up right after joining guest Wi‑Fi, extra redirects or repeated prompts, or a device code you never asked for while just trying to get online. That’s not normal Wi‑Fi behavior. When you travel, treat hotel, conference, and airport Wi‑Fi as untrusted, use your phone’s hotspot instead, and never enter a device code or M365 password you didn’t personally start the sign-in for.

Similar attacks

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login pages or fake update screens. The goal was to steal Microsoft 365 credentials and/or trick victims into installing espionage malware,…

August 3, 2026
Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get…

August 1, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Midnight Blizzard Hijacks Hotel Wi‑Fi to Phish Guests

Midnight Blizzard Hijacks Hotel Wi‑Fi to Phish Guests

Microsoft says a Russia-linked group compromised hotel and conference guest Wi‑Fi sign-in systems to redirect travelers to phishing pages and fake “update” prompts. The goal was to steal credentials (including Microsoft 365) and push malware when devices automatically check connectivity after…

August 4, 2026