Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Help Net Security · High sophistication
Last updated August 4, 2026

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and trick victims into running malware under the guise of browser/OS updates.

Key findings

  • Microsoft named the campaign “CaptiveCrunch” and tied it to Storm-2945, a sub-cluster of Midnight Blizzard.
  • Attackers manipulated DNS/HTTP on compromised captive-portal Wi‑Fi networks at hotels and conference centers to redirect victims.
  • Victims were sent to (1) phishing pages impersonating Microsoft 365 sign-in, (2) device code phishing abusing Microsoft Entra ID flows, or (3) fake update pages using ClickFix to persuade users to download/run malware.
  • Two malware strains were identified: CornFlake (Windows RAT) and ChocoShell (in-memory PowerShell credential stealer).
  • ClickFix pages were also configured to deliver an Android APK, suggesting Android targeting.

Who’s being targeted

  • Commonly targeted roles: Executives, All traveling employees, Government / diplomatic staff, IT administrators, Finance leaders frequently traveling.
  • Affected industries: Government / Diplomacy, Hospitality (hotels, conference centers), Any industry with traveling employees.
  • Attack channels: website.
  • Impersonated: Microsoft 365 sign-in (via the venue’s Wi‑Fi captive portal), Microsoft Entra ID authentication flow, Browser update page or operating system update page.

Awareness takeaways

  • Treat hotel and conference Wi‑Fi as untrusted; use managed connectivity (VPN/cellular hotspot) where possible.
  • Never enter Microsoft 365 credentials (or device codes) into login prompts that appear as part of a guest Wi‑Fi portal flow.
  • Do not install “updates” or “tools” offered by captive portals; only update via trusted device/app update mechanisms.
  • Minimize what employee information is shared with hospitality providers during guest Wi‑Fi registration.

Red flags to watch for

  • Unexpected Microsoft 365 login prompt appears immediately after joining hotel/conference Wi‑Fi
  • Login page is reached through the Wi‑Fi portal flow rather than a known Microsoft URL/bookmark
  • Anything about the page or certificate/URL looks unusual compared to normal corporate sign-in
  • Device-code sign-in is unexpected for routine Wi‑Fi access
  • Instructions push you to authenticate in a way you don’t normally use for your account
  • You are asked to approve a sign-in you didn’t initiate
  • Updates are offered through a hotel/conference Wi‑Fi page instead of the device’s normal update mechanism
  • Pressure/urgency to install immediately to continue browsing
  • Any request to manually download/run an executable (or APK) from a pop-up/update page
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You join hotel Wi‑Fi, and boom, before the internet even works, a perfect Microsoft 365 login pops up. Microsoft calls this campaign CaptiveCrunch. Compromised hotel and conference Wi‑Fi quietly hijack DNS and HTTP, then redirect you to fake Microsoft 365 sign-in, bogus Entra ID device-code pages, or fake update screens that drop CornFlake or ChocoShell malware. The tell: the login or device-code prompt comes as part of the guest Wi‑Fi flow, not from your normal Microsoft URL or bookmark. If hotel Wi‑Fi suddenly wants your work password or a device code, that’s CaptiveCrunch territory. When you travel, treat hotel and conference Wi‑Fi as hostile: if it ever asks for your Microsoft 365 password or a device code, stop, disconnect, and switch to VPN or your phone’s hotspot instead.

Similar attacks

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get…

August 1, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft reports a Russian state-backed operation that compromises hotel and conference Wi‑Fi “captive portals” to redirect travelers to fake Microsoft 365 sign-in pages or fake update prompts that install malware. One method abuses Microsoft’s device-code login flow so victims unknowingly approve…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login pages or fake update screens. The goal was to steal Microsoft 365 credentials and/or trick victims into installing espionage malware,…

August 3, 2026
Captive Portal Trick Hits Travelers With Fake Updates

Captive Portal Trick Hits Travelers With Fake Updates

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to attacker-controlled pages. Victims are pushed into fake Microsoft sign-ins (device code/OAuth phishing) or tricked into installing “browser/OS…

July 31, 2026