Compromised Hotel Wi-Fi Redirects Travelers to Malware and Credential Theft
The CaptiveCrunch campaign hijacks hotel Wi-Fi captive portals and manipulates DNS responses to redirect travelers toward fake software updates, ClickFix instructions, and Microsoft device-code phishing. Microsoft attributes the activity to Storm-2945, an operational cluster linked to the Russia-associated Midnight Blizzard/APT29, although independent confirmation remains limited. Victims who execute the supplied commands may receive CornFlake RAT or ChocoShell, enabling surveillance, credential and token theft, remote access, and persistent control of Windows devices. Travelers should use an always-on, full-tunnel VPN, avoid updates offered through captive portals, and reject unfamiliar device-authentication requests.
Reference: thehackernews.com, microsoft.com