Hotel WiFi Scam Pushes Fake Updates and Malware

Hackaday · Medium sophistication
Last updated August 7, 2026

A Russia-linked threat group compromised hotel WiFi captive portals to redirect guests to fake “verification” pages. Victims were pushed toward either copying commands into a terminal to install malware or entering Microsoft credentials on spoofed login pages that added an attacker-controlled device to their account.

Key findings

  • Attackers compromised hotel WiFi captive portals/gateways and hijacked DNS to redirect users to fake verification pages.
  • One path used “click-to-fix” style prompts that tricked users into copying/pasting terminal commands that install malware.
  • Another path used Microsoft-lookalike login pages to capture sign-ins and then prompt victims to paste an authentication URL that adds a new device to the Microsoft account.
  • The campaign relied on users ignoring browser security warnings like invalid SSL certificate alerts.

Who’s being targeted

  • Commonly targeted roles: All employees who travel, Executives, Sales, Consultants, IT helpdesk (for traveler guidance).
  • Affected industries: Hotels / hospitality, Business travelers (cross-industry corporate users), Consumer/home users.
  • Attack channels: website.
  • Impersonated: Hotel WiFi captive portal / network verification page, Microsoft (spoofed sign-in page).

Awareness takeaways

  • Treat public WiFi “verification” steps as suspicious, never run terminal commands to get online.
  • Don’t enter Microsoft 365 credentials into a WiFi portal page; verify the domain and use known sign-in paths.
  • Heed browser security warnings (like invalid SSL certificates) instead of clicking through.
  • For corporate travelers, reduce exposure on public WiFi by using an always-on corporate VPN with company-controlled DNS.

Red flags to watch for

  • WiFi portal asks you to run terminal/shell commands to get internet access
  • Browser warns about an invalid SSL certificate
  • Verification step is unrelated to normal hotel WiFi login (room/name/payment)
  • A public WiFi portal demands Microsoft 365 login to get internet access
  • Login page is hosted on a lookalike/copycat domain
  • After signing in, you’re asked to copy/paste a URL to “authenticate” a device
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in a hotel, you join the WiFi… and the portal suddenly wants you to “run a command” to get online. This is a hijacked hotel WiFi portal. One path is a fake “click‑to‑fix” page telling you to paste that string into Terminal or PowerShell, behind the scenes, it installs malware. Another path: you’re redirected to a Microsoft‑lookalike login page saying you must sign in to use the Internet. It’s on a copycat domain, and after you sign in, it tells you to paste an “authentication URL” that secretly adds a new device to your Microsoft account. Here’s the move: on any hotel or public WiFi, if the portal ever tells you to run Terminal or PowerShell commands, or to sign in with Microsoft to get online, stop and call IT before you do anything.

Categories

Similar attacks

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Hackers Hijack Hotel Wi‑Fi to Push Fake Updates

Hackers Hijack Hotel Wi‑Fi to Push Fake Updates

Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake browser/OS update prompts (and sometimes “paste-and-run” instructions) to install malware, and later were pushed into Microsoft device-code…

August 3, 2026
Captive Portal Trick Hits Travelers With Fake Updates

Captive Portal Trick Hits Travelers With Fake Updates

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to attacker-controlled pages. Victims are pushed into fake Microsoft sign-ins (device code/OAuth phishing) or tricked into installing “browser/OS…

July 31, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026