Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Help Net Security · High sophistication
Last updated August 4, 2026

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and trick victims into running malware under the guise of browser/OS updates.

Key findings

  • Microsoft named the campaign “CaptiveCrunch” and tied it to Storm-2945, a sub-cluster of Midnight Blizzard.
  • Attackers manipulated DNS/HTTP on compromised captive-portal Wi‑Fi networks at hotels and conference centers to redirect victims.
  • Victims were sent to (1) phishing pages impersonating Microsoft 365 sign-in, (2) device code phishing abusing Microsoft Entra ID flows, or (3) fake update pages using ClickFix to persuade users to download/run malware.
  • Two malware strains were identified: CornFlake (Windows RAT) and ChocoShell (in-memory PowerShell credential stealer).
  • ClickFix pages were also configured to deliver an Android APK, suggesting Android targeting.

Who’s being targeted

  • Commonly targeted roles: Executives, All traveling employees, Government / diplomatic staff, IT administrators, Finance leaders frequently traveling.
  • Affected industries: Government / Diplomacy, Hospitality (hotels, conference centers), Any industry with traveling employees.
  • Attack channels: website.
  • Impersonated: Microsoft 365 sign-in (via the venue’s Wi‑Fi captive portal), Microsoft Entra ID authentication flow, Browser update page or operating system update page.

Awareness takeaways

  • Treat hotel and conference Wi‑Fi as untrusted; use managed connectivity (VPN/cellular hotspot) where possible.
  • Never enter Microsoft 365 credentials (or device codes) into login prompts that appear as part of a guest Wi‑Fi portal flow.
  • Do not install “updates” or “tools” offered by captive portals; only update via trusted device/app update mechanisms.
  • Minimize what employee information is shared with hospitality providers during guest Wi‑Fi registration.

Red flags to watch for

  • Unexpected Microsoft 365 login prompt appears immediately after joining hotel/conference Wi‑Fi
  • Login page is reached through the Wi‑Fi portal flow rather than a known Microsoft URL/bookmark
  • Anything about the page or certificate/URL looks unusual compared to normal corporate sign-in
  • Device-code sign-in is unexpected for routine Wi‑Fi access
  • Instructions push you to authenticate in a way you don’t normally use for your account
  • You are asked to approve a sign-in you didn’t initiate
  • Updates are offered through a hotel/conference Wi‑Fi page instead of the device’s normal update mechanism
  • Pressure/urgency to install immediately to continue browsing
  • Any request to manually download/run an executable (or APK) from a pop-up/update page
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You join hotel Wi‑Fi, and boom, before the internet even works, a perfect Microsoft 365 login pops up. Microsoft calls this campaign CaptiveCrunch. Compromised hotel and conference Wi‑Fi quietly hijack DNS and HTTP, then redirect you to fake Microsoft 365 sign-in, bogus Entra ID device-code pages, or fake update screens that drop CornFlake or ChocoShell malware. The tell: the login or device-code prompt comes as part of the guest Wi‑Fi flow, not from your normal Microsoft URL or bookmark. If hotel Wi‑Fi suddenly wants your work password or a device code, that’s CaptiveCrunch territory. When you travel, treat hotel and conference Wi‑Fi as hostile: if it ever asks for your Microsoft 365 password or a device code, stop, disconnect, and switch to VPN or your phone’s hotspot instead.

Similar attacks

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get…

August 1, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Russian Spy Phish Uses Legit OAuth Logins

Russian Spy Phish Uses Legit OAuth Logins

Google says three suspected Russian cyber-espionage groups are running highly targeted phishing campaigns against people in government, academia, defense, and think tanks in the US and Europe. A key theme is abusing legitimate Google/Microsoft OAuth login flows so the outreach looks real, tricking…

August 21, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026