
Fake Claude App and Alert Apps Drive New Scams
This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…
Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled phishing pages. Victims were tricked into installing malware disguised as browser/operating system updates, and some pages redirected users into Microsoft device-code sign-in flows to steal access.
This campaign targeted people connecting to hotel Wi-Fi networks that use captive portals, the login pages you see before internet access is granted. Attackers manipulated DNS and HTTP traffic on these networks, effectively placing themselves in an adversary-in-the-middle position between the victim and the internet. From there, they redirected users through actor-controlled phishing infrastructure instead of the legitimate hotel login flow.
One path pushed malware disguised as a browser or operating system update. This wasn't a random pop-up: it was triggered by automated connectivity checks that browsers issue when joining a new network, giving the fake update prompt an air of legitimacy. Another path redirected some landing pages into Microsoft device code authentication flows, a real sign-in mechanism that, if abused this way, can be used to capture access to a victim's account.
The attack exploited a moment of low suspicion: joining hotel Wi-Fi. Travelers expect a login page and often expect some friction before getting online, so an update prompt or a sign-in request doesn't immediately stand out. Because the manipulation happened at the network level, the redirect could appear on a page that otherwise looked like a normal captive portal, with no obvious sign that traffic had been rerouted through attacker infrastructure.
The use of a real Microsoft authentication mechanism, device code sign-in, added another layer of legitimacy. Most people have never seen a device code prompt and have no baseline for what a suspicious one looks like.
Traveling employees, executives, sales staff, and anyone using Microsoft 365 single sign-on should treat network-level prompts with skepticism by default. Update software only through official mechanisms, never through a link or download offered by a Wi-Fi login page. Device code sign-in requests should be treated as a red flag unless you personally started that sign-in process on another device; if one appears unexpectedly, stop and report it. Because redirects on public networks are not proof of legitimacy, the safest habit while traveling is to verify any unexpected prompt independently rather than acting on it in the moment.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They manipulated DNS and HTTP traffic on networks served by captive portals, redirecting users through attacker-controlled infrastructure to phishing pages while the victim believed they were simply connecting to hotel internet.
The malware was delivered in response to normal automated connectivity checks issued by browsers, so victims saw an update prompt that appeared right after joining the network rather than through an official update channel.
Some captive-portal landing pages redirected victims into a device code authentication flow, a known method attackers use to steal sign-in access, especially risky if the prompt appears unexpectedly during a Wi-Fi login.
Executives, sales staff, consultants, finance and IT personnel, and any Microsoft 365 users who travel and connect to hotel or public Wi-Fi are the primary targets.
You join hotel Wi‑Fi, and instantly see: “Your browser requires an update to access the internet.” Looks normal, right? Microsoft says a group called Storm‑2945 hijacks hotel Wi‑Fi captive portals, manipulating DNS and HTTP so your traffic quietly detours through their servers. They use that spot to push malware that pretends to be a browser or OS update. Here’s the twist: some CaptiveCrunch pages don’t push a file at all. They bounce you into a Microsoft device‑code sign‑in that looks legit, then steal your sign‑in tokens. You think you’re just connecting to Wi‑Fi; they’re quietly taking your Microsoft 365 access. If hotel Wi‑Fi ever demands a software install or surprise Microsoft device‑code sign‑in, stop. Close the page and report it to IT, don’t install, don’t approve, just report.

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

Microsoft and ReliaQuest report a real campaign where attackers tampered with public Wi‑Fi captive portal networks (hotels/conference venues) to redirect users…

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into…

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login…