Hotel WiFi Scam Pushes Fake Updates and Malware

Hackaday · Medium sophistication
Last updated August 7, 2026

A Russia-linked threat group compromised hotel WiFi captive portals to redirect guests to fake “verification” pages. Victims were pushed toward either copying commands into a terminal to install malware or entering Microsoft credentials on spoofed login pages that added an attacker-controlled device to their account.

Key findings

  • Attackers compromised hotel WiFi captive portals/gateways and hijacked DNS to redirect users to fake verification pages.
  • One path used “click-to-fix” style prompts that tricked users into copying/pasting terminal commands that install malware.
  • Another path used Microsoft-lookalike login pages to capture sign-ins and then prompt victims to paste an authentication URL that adds a new device to the Microsoft account.
  • The campaign relied on users ignoring browser security warnings like invalid SSL certificate alerts.

Who’s being targeted

  • Commonly targeted roles: All employees who travel, Executives, Sales, Consultants, IT helpdesk (for traveler guidance).
  • Affected industries: Hotels / hospitality, Business travelers (cross-industry corporate users), Consumer/home users.
  • Attack channels: website.
  • Impersonated: Hotel WiFi captive portal / network verification page, Microsoft (spoofed sign-in page).

Awareness takeaways

  • Treat public WiFi “verification” steps as suspicious, never run terminal commands to get online.
  • Don’t enter Microsoft 365 credentials into a WiFi portal page; verify the domain and use known sign-in paths.
  • Heed browser security warnings (like invalid SSL certificates) instead of clicking through.
  • For corporate travelers, reduce exposure on public WiFi by using an always-on corporate VPN with company-controlled DNS.

Red flags to watch for

  • WiFi portal asks you to run terminal/shell commands to get internet access
  • Browser warns about an invalid SSL certificate
  • Verification step is unrelated to normal hotel WiFi login (room/name/payment)
  • A public WiFi portal demands Microsoft 365 login to get internet access
  • Login page is hosted on a lookalike/copycat domain
  • After signing in, you’re asked to copy/paste a URL to “authenticate” a device
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in a hotel, you join the WiFi… and the portal suddenly wants you to “run a command” to get online. This is a hijacked hotel WiFi portal. One path is a fake “click‑to‑fix” page telling you to paste that string into Terminal or PowerShell, behind the scenes, it installs malware. Another path: you’re redirected to a Microsoft‑lookalike login page saying you must sign in to use the Internet. It’s on a copycat domain, and after you sign in, it tells you to paste an “authentication URL” that secretly adds a new device to your Microsoft account. Here’s the move: on any hotel or public WiFi, if the portal ever tells you to run Terminal or PowerShell commands, or to sign in with Microsoft to get online, stop and call IT before you do anything.

Categories

Similar attacks

Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Hackers Hijack Hotel Wi‑Fi to Push Fake Updates

Hackers Hijack Hotel Wi‑Fi to Push Fake Updates

Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake browser/OS update prompts (and sometimes “paste-and-run” instructions) to install malware, and later were pushed into Microsoft device-code…

August 3, 2026