Tuesday, August 11, 2026 Latest Microsoft Warns Travelers Against Using Free Hotel Wi-Fi Our standards
Technology

Microsoft Warns Travelers Against Using Free Hotel Wi-Fi

Microsoft has issued a warning to travelers advising them against connecting to free Wi-Fi networks in hotels, airports, and convention centers following the detection of a hacking campaign aimed at deploying malware, stealing passwords, and harvesting sensitive data, according to Youm7.

According to the Microsoft Threat Intelligence unit, the campaign—designated as CaptiveCrunch—began its activity in early May 2026 and specifically targets hospitality networks globally. Microsoft links the campaign to Storm-2945, a subgroup of the Russia-linked group Midnight Blizzard, which is also known as APT29 or Cozy Bear. The hackers appear to place a particular focus on business travelers to gain access to their professional accounts and corporate data.

Method of Attack and Fake Updates

The campaign operates by manipulating DNS and HTTP traffic inside networks that utilize a captive portal, which is the login or terms-of-service page that typically appears when connecting to a public Wi-Fi network. Hackers exploit this mechanism to redirect users to infrastructure and websites under their control instead of authentic connection pages. Compromised Wi-Fi networks have been detected across hospitality organizations and shared public locations in multiple countries.

Once connected to a fake page, users may encounter a popup window requesting the installation of an update or a fix for a connection issue. While presented as an operating system or browser update, the prompt can deliver malware that grants attackers system access and data theft capabilities. The campaign utilizes pages styled to resemble Windows or browser updates, while other pages masquerade as Google security checks requiring user verification. Android users may additionally be prompted to download and install an APK file, resulting in malware infection.

Credential Theft and Malware Capabilities

Beyond malware distribution, the threat group employs device-code phishing to compromise login credentials. Victims may be redirected to a genuine Microsoft login page and prompted to enter a specific code; although the page appears authentic, entering the code permits attackers to hijack the user session and seize the account. Once a device or account is compromised, operators can record screen activity, capture keystrokes, steal login data, and record audio and video.

Microsoft identified two specific malware strains utilized in the campaign: CornFlake and ChocoShell. CornFlake is capable of stealing files, passwords, and login credentials, alongside capturing screenshots and recording audio and video from the infected device. ChocoShell targets browser cookies, saved passwords, Microsoft 365 login data, and stored Wi-Fi network passwords.

تحذير من مايكروسوفت: لماذا يجب ألا تستخدم واي فاي الفنادق مجدداً
Accuracy matters. See something that needs attention? Read our corrections policy or contact the newsroom.

Technology Editor

Maya Serrano

Maya Serrano is the editorial identity for TellingPointy's Technology desk, covering artificial intelligence, platforms, software, hardware, cybersecurity, and digital policy. Serrano's work translates complex systems without sanding away the important details. Her desk asks who controls a technology, what data and incentives power it, where the real limits sit, and how a product or policy changes the balance among users, companies, governments, and the wider public.