Microsoft has issued a warning to travelers advising them against connecting to free Wi-Fi networks in hotels, airports, and convention centers following the detection of a hacking campaign aimed at deploying malware, stealing passwords, and harvesting sensitive data, according to Youm7.
According to the Microsoft Threat Intelligence unit, the campaign—designated as CaptiveCrunch—began its activity in early May 2026 and specifically targets hospitality networks globally. Microsoft links the campaign to Storm-2945, a subgroup of the Russia-linked group Midnight Blizzard, which is also known as APT29 or Cozy Bear. The hackers appear to place a particular focus on business travelers to gain access to their professional accounts and corporate data.
Method of Attack and Fake Updates
The campaign operates by manipulating DNS and HTTP traffic inside networks that utilize a captive portal, which is the login or terms-of-service page that typically appears when connecting to a public Wi-Fi network. Hackers exploit this mechanism to redirect users to infrastructure and websites under their control instead of authentic connection pages. Compromised Wi-Fi networks have been detected across hospitality organizations and shared public locations in multiple countries.
Once connected to a fake page, users may encounter a popup window requesting the installation of an update or a fix for a connection issue. While presented as an operating system or browser update, the prompt can deliver malware that grants attackers system access and data theft capabilities. The campaign utilizes pages styled to resemble Windows or browser updates, while other pages masquerade as Google security checks requiring user verification. Android users may additionally be prompted to download and install an APK file, resulting in malware infection.
Credential Theft and Malware Capabilities
Beyond malware distribution, the threat group employs device-code phishing to compromise login credentials. Victims may be redirected to a genuine Microsoft login page and prompted to enter a specific code; although the page appears authentic, entering the code permits attackers to hijack the user session and seize the account. Once a device or account is compromised, operators can record screen activity, capture keystrokes, steal login data, and record audio and video.
Microsoft identified two specific malware strains utilized in the campaign: CornFlake and ChocoShell. CornFlake is capable of stealing files, passwords, and login credentials, alongside capturing screenshots and recording audio and video from the infected device. ChocoShell targets browser cookies, saved passwords, Microsoft 365 login data, and stored Wi-Fi network passwords.