
Hacked Wi‑Fi Portals Steal M365 Logins
Microsoft and ReliaQuest report a real campaign where attackers tampered with public Wi‑Fi captive portal networks (hotels/conference venues) to redirect users…
Microsoft says Russian SVR operators (Storm-2945/Midnight Blizzard) are compromising public Wi‑Fi captive portals in hotels and conference venues to redirect users to attacker-controlled pages. Those pages use fake “fix/verification/update” prompts to trick travelers into installing malware or completing “device code” sign-ins that hand over Microsoft 365 access tokens.
Microsoft attributes this campaign to Storm-2945, a group linked to Russia's SVR and tracked as Midnight Blizzard. The operation targets public Wi-Fi users in hospitality venues such as hotels and conference centers. After compromising a location's captive portal, the attackers manipulate DNS and HTTP traffic to reroute connecting users through attacker-controlled infrastructure, a classic adversary-in-the-middle setup that sits between the victim and the internet.
Once redirected, victims see ClickFix-style prompts disguised as OS updates, driver repairs, or web verification failures. Following the prompt's instructions can install malware, primarily on Windows machines, though Microsoft has also seen Android-tailored prompts urging users to sideload an APK file. The malware families observed include CornFlake, a persistent remote access trojan, and ChocoShell, an in-memory infostealer that harvests cookies, passwords, SSO tokens, and Wi-Fi credentials.
A second track uses device code phishing. Some redirected pages instruct users to copy a code, open a legitimate Microsoft authentication page, and enter that code to "connect." Completing this flow authenticates the attacker into the chosen account, handing over a valid OAuth token for the victim's Microsoft 365 account.
The attack exploits the routine trust travelers place in hotel and conference Wi-Fi. A prompt to "fix" connectivity or verify identity feels like a normal part of getting online, so it doesn't trigger the same suspicion an unsolicited email might. Because the compromise happens at the network level, the malicious redirect can appear consistent with the venue's own portal, making it harder for a typical user to distinguish it from a legitimate step.
The device code flow is especially effective because the authentication itself happens on a genuine Microsoft page. Victims are not entering credentials into a fake site, they are completing a real sign-in, just one initiated by an attacker rather than themselves.
Treat any install prompt from a public Wi-Fi portal as untrusted, since legitimate networks rarely require software installs to grant access. Never complete a device code sign-in unless you personally initiated it, and report unexpected code prompts right away. Favoring personal hotspots or satellite connections over shared hotel and conference networks reduces exposure. Organizations can further reduce risk by disabling device code authentication where feasible, removing this particular path for attackers to seize workplace cloud access.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromise public Wi-Fi captive portals and manipulate DNS/HTTP traffic to redirect users to attacker-controlled pages that show fake update or verification prompts, tricking victims into installing malware or completing a device code sign-in.
Microsoft identified CornFlake, a persistent remote access trojan, and ChocoShell, an in-memory infostealer that targets cookies, passwords, SSO tokens, and Wi-Fi credentials.
Victims are told to enter a code the attacker generated into a legitimate Microsoft sign-in page, which unwittingly authorizes the attacker's session and hands over a valid OAuth token for the victim's Microsoft 365 account.
Microsoft recommends reducing trust in public Wi-Fi, favoring personal hotspots or satellite connections over hotel networks, and disabling device code authentication where feasible.
You connect to hotel Wi‑Fi, and instantly see: “Web verification failure – install this Windows fix to get online.” Microsoft says SVR group Storm-2945 is hijacking hotel and conference Wi‑Fi like this, swapping the real portal for their own page to push fake ClickFix-style “OS updates” and Android APKs that quietly drop CornFlake and ChocoShell malware. Their nastiest trick: the portal tells you to copy a Microsoft device code, open the real Microsoft sign‑in page, and enter it. You feel safe because the site is legit, but you’ve just handed them a valid OAuth token into your Microsoft 365. If public Wi‑Fi ever asks you to install a fix or use a device code, stop. Kill the page, switch to your phone’s hotspot, and report it to security.

Microsoft and ReliaQuest report a real campaign where attackers tampered with public Wi‑Fi captive portal networks (hotels/conference venues) to redirect users…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

Microsoft reports a real-world campaign where attackers tamper with Wi‑Fi captive portal traffic at hotels and similar venues to redirect travelers to…

Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled…

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

Researchers report attackers compromising hotel and venue Wi‑Fi “captive portal” gateways to redirect Microsoft 365 sign-ins to attacker-controlled lookalike…