
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins
Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login…
Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get victims to run commands or install a malware implant. Some pages also pushed victims into Microsoft’s legitimate “device code” login flow to capture MFA-approved access.
Attackers gained administrative control over hotel and venue captive-portal gateways and used that access to forge DNS answers. When a traveler's laptop performed its normal automatic connectivity check after joining hotel Wi-Fi, the forged DNS response redirected the device to a fake browser or operating system update page instead of the real internet. From there, the campaign, tracked as CaptiveCrunch, used several follow-on tactics: prompting victims to download and run a fake update installer, presenting ClickFix-style instructions that told users to open a terminal or Windows utility and run an attacker-supplied command, and in some cases redirecting guests into Microsoft's legitimate device code authentication flow.
The attack did not rely on silent exploitation. The gateway controlled where the user was sent, but the victim still had to download or execute the payload themselves. This worked because travelers expect to see update prompts, login screens, or troubleshooting steps when joining unfamiliar hotel networks, and they are primed to comply quickly to get online. The device code abuse was especially effective because the login page shown to the victim was Microsoft's real sign-in page, entering the attacker-supplied code there granted an attacker-controlled session that was already MFA-satisfied.
Organizations should train traveling employees, executives, sales staff, and other Microsoft 365 users to treat captive-portal prompts for updates, certificates, or troubleshooting tools as suspicious and to never install software just to get online. Staff should also be taught to pause and verify with IT before entering any device code or approving an authentication flow triggered by a public Wi-Fi login page. On the technical side, using an always-on, full-tunnel corporate VPN sends DNS queries through corporate resolvers before a venue's gateway can respond, reducing the window for this kind of redirection. Conditional Access policies that restrict device code flows where they are not needed can also limit the impact of this technique. Because this campaign targets hospitality networks and business travelers across multiple countries, awareness training focused specifically on public Wi-Fi behavior is a practical way to reduce exposure.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
CaptiveCrunch is a campaign where attackers with admin control of hotel captive-portal gateways forged DNS answers to redirect travelers to fake browser or OS update pages, tricking them into installing malware.
The gateway only controls where a user is redirected, it does not silently infect the endpoint. The victim still has to download or manually execute the payload, sometimes through ClickFix-style instructions to run a command in a terminal or Windows utility.
Some captive portal pages push guests into Microsoft's legitimate device code authentication flow. Entering the attacker-supplied code on Microsoft's real sign-in page can grant the attacker an MFA-satisfied session.
Reject any software updates, certificates, or troubleshooting tools offered through a captive portal, and use an always-on full-tunnel VPN so DNS queries route through corporate resolvers before the hotel gateway can respond.
You connect to hotel Wi‑Fi and boom, before the internet loads, a page says: “Browser update required to go online.” In the CaptiveCrunch campaign, hijacked hotel gateways redirected laptops’ connectivity checks to fake browser or OS update pages, pushing spyware like CornFlake and ChocoShell, only if you downloaded or ran their installer. Some pages even used ClickFix-style steps: 'Open PowerShell and paste this command,' or pushed you into a Microsoft device code sign-in where entering their code quietly gave them MFA-approved access. Aha moment: hotel Wi‑Fi should never make you install software or run commands. If a captive portal offers an update or fix, stop, and get online through your full‑tunnel corporate VPN instead.

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login…

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled…

Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake…

Microsoft reported a real campaign where Russian-linked attackers tampered with hotel and conference Wi‑Fi “captive portals” to redirect travelers to…