Hijacked Hotel Wi‑Fi Serves Fake Updates

The Hacker News · High sophistication
Last updated August 1, 2026

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get victims to run commands or install a malware implant. Some pages also pushed victims into Microsoft’s legitimate “device code” login flow to capture MFA-approved access.

How the attack worked

Attackers gained administrative control over hotel and venue captive-portal gateways and used that access to forge DNS answers. When a traveler's laptop performed its normal automatic connectivity check after joining hotel Wi-Fi, the forged DNS response redirected the device to a fake browser or operating system update page instead of the real internet. From there, the campaign, tracked as CaptiveCrunch, used several follow-on tactics: prompting victims to download and run a fake update installer, presenting ClickFix-style instructions that told users to open a terminal or Windows utility and run an attacker-supplied command, and in some cases redirecting guests into Microsoft's legitimate device code authentication flow.

Why it succeeded

The attack did not rely on silent exploitation. The gateway controlled where the user was sent, but the victim still had to download or execute the payload themselves. This worked because travelers expect to see update prompts, login screens, or troubleshooting steps when joining unfamiliar hotel networks, and they are primed to comply quickly to get online. The device code abuse was especially effective because the login page shown to the victim was Microsoft's real sign-in page, entering the attacker-supplied code there granted an attacker-controlled session that was already MFA-satisfied.

What to watch for

  • An unexpected update prompt appearing immediately after joining hotel Wi-Fi, especially one served by the captive portal itself rather than the operating system or browser vendor
  • Instructions asking you to open Terminal, PowerShell, or another Windows utility and paste in a command just to "fix" connectivity or install an update
  • Being asked to enter a device code to get internet access, particularly if the request comes from a Wi-Fi login page rather than your own corporate device or app
  • Any troubleshooting tool, certificate, or security utility offered through a public Wi-Fi login screen

How to build resistance

Organizations should train traveling employees, executives, sales staff, and other Microsoft 365 users to treat captive-portal prompts for updates, certificates, or troubleshooting tools as suspicious and to never install software just to get online. Staff should also be taught to pause and verify with IT before entering any device code or approving an authentication flow triggered by a public Wi-Fi login page. On the technical side, using an always-on, full-tunnel corporate VPN sends DNS queries through corporate resolvers before a venue's gateway can respond, reducing the window for this kind of redirection. Conditional Access policies that restrict device code flows where they are not needed can also limit the impact of this technique. Because this campaign targets hospitality networks and business travelers across multiple countries, awareness training focused specifically on public Wi-Fi behavior is a practical way to reduce exposure.

Key findings

  • Attackers with admin control of captive-portal gateways forged DNS answers to redirect victims to fake update pages.
  • Victims were tricked into manual execution (ClickFix-style) rather than being silently exploited: the user had to download or run the payload.
  • Campaign targeted hospitality networks in multiple countries and focused on travelers.
  • Some landing pages redirected victims into Microsoft’s device code authentication flow, where entering an attacker-provided code could grant MFA-satisfied access.
  • Malware referenced includes CornFlake (RAT capabilities like webcam/mic/keystroke capture) and ChocoShell (token-stealing via PowerShell).

Who’s being targeted

  • Commonly targeted roles: All employees who travel, Executives, Sales and field teams, Microsoft 365 users, IT/Helpdesk (for traveler guidance).
  • Affected industries: Hospitality (hotels, venues with captive portals), Travel (business travelers), Any corporate users connecting from public Wi‑Fi.
  • Attack channels: website.
  • Impersonated: Browser/Operating System update prompt (served via hotel captive portal), Captive portal “support” / update instructions, Microsoft sign-in / device code authentication (abused).

Red flags to watch for

  • Unexpected update prompt appears immediately after joining hotel Wi‑Fi/captive portal
  • Update is offered by the Wi‑Fi login page instead of the official vendor update mechanism
  • User is asked to install software just to get internet access
  • Portal asks you to open Terminal/PowerShell/Windows utilities for a “browser update”
  • Copy/paste command execution is requested from a web page
  • Fix/update steps are presented by the Wi‑Fi login system rather than IT or the software vendor
  • Being asked to enter a device code from a Wi‑Fi portal to access the internet
  • Login flow initiated unexpectedly right after joining public Wi‑Fi
  • A code is provided by a third-party page (captive portal) rather than your corporate app/device
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the CaptiveCrunch attack?

CaptiveCrunch is a campaign where attackers with admin control of hotel captive-portal gateways forged DNS answers to redirect travelers to fake browser or OS update pages, tricking them into installing malware.

How does the fake update trick actually infect a device?

The gateway only controls where a user is redirected, it does not silently infect the endpoint. The victim still has to download or manually execute the payload, sometimes through ClickFix-style instructions to run a command in a terminal or Windows utility.

Why is the Microsoft device code redirect dangerous?

Some captive portal pages push guests into Microsoft's legitimate device code authentication flow. Entering the attacker-supplied code on Microsoft's real sign-in page can grant the attacker an MFA-satisfied session.

How can travelers protect themselves on hotel Wi-Fi?

Reject any software updates, certificates, or troubleshooting tools offered through a captive portal, and use an always-on full-tunnel VPN so DNS queries route through corporate resolvers before the hotel gateway can respond.

Read the video transcript

You connect to hotel Wi‑Fi and boom, before the internet loads, a page says: “Browser update required to go online.” In the CaptiveCrunch campaign, hijacked hotel gateways redirected laptops’ connectivity checks to fake browser or OS update pages, pushing spyware like CornFlake and ChocoShell, only if you downloaded or ran their installer. Some pages even used ClickFix-style steps: 'Open PowerShell and paste this command,' or pushed you into a Microsoft device code sign-in where entering their code quietly gave them MFA-approved access. Aha moment: hotel Wi‑Fi should never make you install software or run commands. If a captive portal offers an update or fix, stop, and get online through your full‑tunnel corporate VPN instead.

Categories

Similar attacks

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft reports a Russian state-backed operation that compromises hotel and conference Wi‑Fi “captive portals” to redirect travelers to fake Microsoft 365 sign-in pages or fake update prompts that install malware. One method abuses Microsoft’s device-code login flow so victims unknowingly approve…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login pages or fake update screens. The goal was to steal Microsoft 365 credentials and/or trick victims into installing espionage malware,…

August 3, 2026
Captive Portal Trick Hits Travelers With Fake Updates

Captive Portal Trick Hits Travelers With Fake Updates

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to attacker-controlled pages. Victims are pushed into fake Microsoft sign-ins (device code/OAuth phishing) or tricked into installing “browser/OS…

July 31, 2026