Russian Hackers Hijack Hotel Wi‑Fi Login Pages

eSecurity Planet · High sophistication
Last updated August 4, 2026

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker access. Even if a laptop is later cleaned, stolen session tokens or device-code approvals can keep the attacker’s cloud access alive after the trip.

Key findings

  • Microsoft uncovered a campaign (“CaptiveCrunch”) that abuses compromised hospitality Wi‑Fi captive portals to deliver malware and steal credentials from travelers.
  • Attackers manipulate DNS and unencrypted HTTP during the connectivity check, redirecting selected users to attacker-controlled pages that look like normal Wi‑Fi setup steps.
  • Lures include fake Windows/browser updates, bogus driver/security fixes, “ClickFix” instructions to copy/paste and run commands, and device-code phishing that authorizes the attacker’s session.
  • Infection is not automatic: the attacker relies on the user to run a file, execute a command, or approve a sign-in request.
  • Post-compromise tooling described includes CornFlake (RAT), ChocoShell (cookie/password/token theft), and FruitStone (management dashboard).
  • Stolen session tokens and device-code authorizations can persist in the cloud even after a device is cleaned or reimaged, creating an identity incident beyond the endpoint.
  • Mitigations highlighted include avoiding guest Wi‑Fi when possible, rejecting portal-supplied updates/certs/commands, using properly configured always-on full-tunnel VPN, and restricting/blocking unnecessary device-code auth.

Who’s being targeted

  • Commonly targeted roles: All employees who travel, Executives, Sales, Consultants/Professional Services, IT/Helpdesk, Microsoft 365 users, Anyone with access to sensitive email/files.
  • Affected industries: Hospitality (hotels/venues), Any organization with traveling employees (cross-industry).
  • Attack channels: website.
  • Impersonated: Hotel Wi‑Fi captive portal / Windows or browser update prompt, Hotel Wi‑Fi captive portal / “network support” instructions, Microsoft sign-in flow (legitimate page) plus attacker-provided device code.

Awareness takeaways

  • Treat any Wi‑Fi login page that offers software updates, drivers, or certificates as suspicious; only update through trusted built-in updaters.
  • Never run copy/paste commands or “fix tools” provided by a captive portal or pop-up during Wi‑Fi connection.
  • Report and do not approve unexpected Microsoft authorization prompts; device-code flows can grant attackers access even after you leave the hotel.
  • Prefer cellular/hotspot over guest Wi‑Fi; if you must use guest Wi‑Fi, use an always-on, full-tunnel VPN configured to protect DNS before the hotel gateway sees it.

Red flags to watch for

  • Updates are offered by the Wi‑Fi login page instead of the normal Windows/browser updater
  • Unexpected update/driver prompt appears during Wi‑Fi sign-in
  • Pressure to install software just to get internet access
  • Any portal that asks you to run commands is abnormal for Wi‑Fi access
  • Copy/paste command instructions during Wi‑Fi login
  • Troubleshooting utilities provided by an untrusted connection page
  • Unexpected Microsoft authorization request during Wi‑Fi setup
  • Being told to use a code you did not initiate yourself
  • Sign-in approval request that doesn’t match what you’re trying to do
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in a hotel, you click “Connect to Wi‑Fi”… and the login page suddenly says you need a Windows or browser update to get online. Microsoft calls this CaptiveCrunch: compromised hotel Wi‑Fi portals that inject fake updates, ClickFix-style copy‑paste commands, or even a Microsoft sign‑in box that secretly approves the attacker’s session. Here’s the nasty part: joining the Wi‑Fi isn’t what gets you. It’s when you run their file, paste their command, or approve that device‑code sign‑in. That can give them cloud access that survives even after your laptop is wiped. Aha moment: hotel Wi‑Fi should NEVER ask you to install software or run commands. If it does, stop, disconnect, and report it, then use cellular or your VPN instead.

Categories

Similar attacks

Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get…

August 1, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft reports a Russian state-backed operation that compromises hotel and conference Wi‑Fi “captive portals” to redirect travelers to fake Microsoft 365 sign-in pages or fake update prompts that install malware. One method abuses Microsoft’s device-code login flow so victims unknowingly approve…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login pages or fake update screens. The goal was to steal Microsoft 365 credentials and/or trick victims into installing espionage malware,…

August 3, 2026
Captive Portal Trick Hits Travelers With Fake Updates

Captive Portal Trick Hits Travelers With Fake Updates

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to attacker-controlled pages. Victims are pushed into fake Microsoft sign-ins (device code/OAuth phishing) or tricked into installing “browser/OS…

July 31, 2026