Stayed in a hotel recently? You might want to check your computer!!

If your job has you checking into hotels for conferences, client visits, or site work, here’s a headline worth pausing on: Microsoft just confirmed that a Russian state-sponsored hacking group has been actively hijacking hotel Wi-Fi networks to steal credentials and plant spyware on travelers’ devices.

This isn’t a hypothetical. It’s happening right now, and it’s a good reminder that the network you connect to matters just as much as the device you’re carrying.

What’s Actually Happening

According to a Microsoft report published July 31, a group tracked as Storm-2945 — a sub-cluster of the Russian espionage outfit Midnight Blizzard (also known as APT29 or Cozy Bear, believed to be tied to Russia’s Foreign Intelligence Service) — has been compromising the “captive portal” login pages hotels use for guest Wi-Fi.

You know the ones: the page that pops up asking you to click “Connect” or enter your room number before you get internet access. Microsoft says the campaign, first spotted in May, has hit hotels and conference venues across multiple U.S. cities, plus India and Saudi Arabia — with corporate travelers as the apparent primary target.

Here’s how the attack works, in plain terms:

  • Fake Microsoft login pages. Guests get redirected to a convincing but fraudulent Microsoft 365 sign-in screen. Type in your credentials, and the attackers now have them — and potentially your whole email, calendar, and document environment.
  • Fake “update” prompts. Other victims see a phony browser or operating system update screen. This uses a technique called ClickFix, where the “update” actually walks you through installing malware yourself.

Two malware families are doing the heavy lifting once someone bites: CornFlake, a remote access trojan that can log keystrokes, steal saved passwords and tokens, grab files, and even quietly turn on a webcam or microphone; and ChocoShell, a faster-acting credential stealer built to grab browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and — fittingly — Wi-Fi credentials themselves. Microsoft also noted signs the campaign is expanding to Android devices through malicious app downloads.

Interestingly, a separate research firm, ReliaQuest, had earlier linked similar tactics to a different Russian group, APT28 (Fancy Bear), which the UK’s National Cyber Security Centre warned in April was compromising home and small-office routers for the same kind of traffic hijacking. Microsoft’s attribution points instead to the Midnight Blizzard family. Whichever group’s fingerprints are on it, the pattern is the same: shared, semi-trusted networks are a soft target.

Why This Matters Beyond Hotels

ReliaQuest’s warning is the part that should stick with you: this isn’t a hotel problem. Any organization running a captive-portal network — airports, conference centers, co-working spaces, universities, hospitals, event venues — is a plausible next target. Anywhere a stranger’s device connects to a shared login page is a place this technique can work.

For small businesses, consultants, and remote workers in our region who travel for training, client meetings, or industry events, that’s a real exposure. A single stolen Microsoft 365 credential can cascade into a compromised inbox, a business email compromise scam against your clients, or a foothold for further intrusion into your systems.

What You Can Actually Do About It

You don’t need a government-grade security team to cut your risk here. A few habits go a long way:

  1. Use a VPN on any hotel, airport, or conference Wi-Fi — no exceptions. A VPN encrypts your traffic before it ever touches the untrusted network, which defeats this entire attack chain.
  2. Treat unexpected “update” prompts on public Wi-Fi as hostile. Legitimate OS and browser updates don’t arrive as a pop-up demanding action the moment you join a hotel network. If you weren’t already updating, don’t click.
  3. Turn on phishing-resistant MFA for Microsoft 365 (security keys or authenticator apps with number matching, not SMS). Even a stolen password is far less useful to an attacker if they can’t complete the second factor.
  4. Use your phone’s hotspot instead of hotel Wi-Fi when you can, especially for anything involving email, financial systems, or client data.
  5. If you’re an IT lead for a small business or nonprofit, consider geo-alerting and conditional access policies on Microsoft 365 sign-ins, so a login attempt from an unfamiliar network or country gets flagged or blocked automatically.

The Bigger Picture

Nation-state actors used to focus their attention on governments and defense contractors. Increasingly, they’re going after the softer underbelly — the everyday infrastructure the rest of us rely on without thinking twice, like a hotel’s Wi-Fi login page. That shift matters for small and mid-sized organizations in Western Maryland and beyond that assume they’re “too small to be a target.” The truth is, you’re not the target — your access is.

If you’d like help auditing your organization’s remote-access practices, building an incident response playbook for credential-theft scenarios, or just want a second opinion before your next work trip, that’s exactly the kind of thing Queen City Cyber Consulting is here for.

Stay sharp out there — and maybe just use the hotspot.

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading