
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins
Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login…
Microsoft reported a real campaign where Russian-linked attackers tampered with hotel and conference Wi‑Fi “captive portals” to redirect travelers to attacker-controlled pages. Victims were tricked into installing malware or completing a Microsoft “device code” sign-in that granted the attacker access, enabling theft of Microsoft 365/Azure AD tokens and potential account takeover.
Microsoft has attributed a campaign called CaptiveCrunch to Storm-2945, an operational sub-cluster of Midnight Blizzard/APT29. Instead of relying on email, the attackers manipulated DNS and HTTP traffic on Wi-Fi networks served by captive portals at hotels, conference centers, and other shared venues. This let them redirect a traveler's traffic through attacker-controlled infrastructure the moment the traveler tried to connect to the internet.
From there, victims were pushed toward ClickFix-style pages disguised as Windows Update screens, Google verification pages, DirectX installers, browser update prompts, or disk optimization utilities, whichever fit the venue. Executing these fake tools delivered malware known as CornFlake, and in some cases credential theft tooling called ChocoShell, which specifically targeted Microsoft 365 and Azure AD tokens, including refresh and WAM tokens, enabling session replay without needing browser cookies.
Starting July 16, some landing pages added a second technique: device code phishing. The attacker initiates a legitimate Microsoft device code authentication request and shows the victim a code to enter on Microsoft's real sign-in page. When the victim completes this step to "connect to Wi-Fi," they actually authenticate the attacker's session, an MFA-satisfied session, since the user just completed the factor.
The attack succeeded because it exploited a moment of low suspicion: joining Wi-Fi at a hotel or conference. Captive portals are expected to ask for some interaction, so a prompt to install a driver, verify a browser, or enter a code does not immediately look out of place. Separately, researchers at ReliaQuest documented attackers compromising Wi-Fi gateways directly and quietly rerouting guests to fake Microsoft login pages, showing this is not a single-technique problem but a pattern across venue networks.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
CaptiveCrunch is a campaign, attributed by Microsoft to Storm-2945 (a sub-cluster of Midnight Blizzard/APT29), that manipulated DNS and HTTP traffic on hotel and conference Wi-Fi captive portals to redirect travelers to attacker-controlled infrastructure.
Fake update pages delivered credential theft tooling called ChocoShell, which targeted Microsoft 365 and Azure AD tokens, including refresh and WAM tokens, allowing attackers to replay sessions without needing browser cookies.
Device code phishing uses Microsoft's legitimate device code sign-in flow: the attacker initiates authentication and gives the victim a code to enter on Microsoft's real page, so the victim unknowingly authenticates the attacker's session with MFA already satisfied.
Treat hotel, conference, and airport Wi-Fi as untrusted, use a mobile hotspot or cellular data when possible, avoid installing anything a captive portal offers as an update or utility, and never enter corporate credentials on venue registration pages.
You know that hotel Wi‑Fi page that pops up before you get online? Storm‑2945 has been hijacking those to steal Microsoft 365 access. In this CaptiveCrunch campaign, they tamper with hotel and conference Wi‑Fi so the portal shows fake Windows Update or Google verification pages, pushing you to download a so‑called fix that’s actually CornFlake malware targeting your Microsoft 365 tokens. Here’s the nasty part: some portals now push a Microsoft device code login. You see a real Microsoft page and type in the code they give you, but that code approves the attacker’s session, giving them your Microsoft 365 and Azure AD access without ever stealing your password. If any hotel, conference, or airport Wi‑Fi ever tells you to download software or use a device code to get online, stop and switch to your phone’s hotspot instead.

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login…

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to…

Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks.…