Russian Hackers Are Targeting Travelers Through Hotel Wi-Fi — How to Protect Your Microsoft 365 Account on the Road
You check into a hotel, open your laptop, connect to the Wi-Fi, and get the usual login portal. Maybe a popup tells you to update your browser before you can browse. You click through — because that's what you always do — and suddenly a Russian intelligence operation has a foothold on your device.
That's not a hypothetical. It's exactly what's happening right now.
What Is CaptiveCrunch?
Microsoft Threat Intelligence has identified an active campaign called CaptiveCrunch, carried out by a group tracked as Storm-2945 — a sub-cluster of the notorious Midnight Blizzard, a Russia-based threat actor attributed by the US and UK governments to the Foreign Intelligence Service of the Russian Federation (the SVR).
Since early May 2026, Storm-2945 has been manipulating DNS and HTTP traffic on compromised hotel, conference center, and hospitality Wi-Fi networks worldwide — networks that use the captive portal login pages you see every time you check into a room or walk into a convention center. Microsoft also notes the broader operation shows signs of AI assistance and dates back to February 2026.
As Help Net Security reports, Microsoft believes the compromises may not be limited to isolated individual venues, citing "notable commonalities in the equipment and management systems used across multiple affected networks" — which suggests the attackers may have found a way into shared infrastructure used by portions of the captive portal ecosystem itself.
In other words: they may not need to hack each hotel separately.
What Happens to the Victim
From your perspective, nothing looks unusual. You connect to the hotel Wi-Fi, you see the usual portal, maybe a familiar-looking message appears. Behind the scenes, however, Storm-2945 has positioned themselves in the network path and can redirect your traffic three different ways:
- Credential phishing — Your browser session is silently redirected to fake Microsoft 365 sign-in pages, where your username, password, OAuth tokens, or device authentication codes are harvested.
- Device code phishing — Fake prompts abuse the Microsoft Entra ID authentication flow to register attacker-controlled devices to your account.
- Malware delivery via fake updates — You're shown a convincing-looking popup claiming you need to install a browser update, a Windows security fix, or a utility tool. If you click through, you download malware.
Microsoft has identified specific fake dialog variants in use, including a bogus Windows Update screen ("Working on updates… Don't turn off your computer"), a fake Windows Security virus scan, a fake DirectX installer, a Visual C++ redistributable prompt, and a fake browser update — among others. These use ClickFix social engineering tactics, sometimes with countdown timers or user counters to pressure you into acting fast.
Meet CornFlake and ChocoShell
Help Net Security details the two malware strains Microsoft identified in these attacks:
CornFlake is a Windows remote access trojan (RAT) written in Go. Its capabilities include keylogging, clipboard monitoring, screenshot capture, audio and video surveillance, browser credential theft, file exfiltration, USB drive monitoring, and remote shell access. When it first runs, it disguises itself by displaying a fake progress window while quietly copying itself to %APPDATA%\svchost32\svchost32.exe and establishing persistence on the machine.
ChocoShell is a fileless PowerShell-based infostealer that runs entirely in memory, targeting browser session cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. As Malwarebytes explains, "where CornFlake provides the operator with a persistent, long-running foothold on the device, ChocoShell is designed to extract the most operationally valuable credentials, giving the operator access to victim cloud environments."
Microsoft also found that the attackers may be targeting Android devices — ClickFix landing pages include instructions for Android users to download and install an APK file.
Why This Matters for Small Business Owners Who Travel
Midnight Blizzard's historical focus is on governments, diplomatic entities, NGOs, and IT service providers — but corporate travelers of all kinds carry exactly what this operation is after: Microsoft 365 credentials, cloud access tokens, and VPN logins that open doors into business networks.
If you're a Yuba City small business owner who travels to trade shows, conferences, or client sites, your laptop is a potential entry point into your entire company's email, files, and systems. One fake "browser update" popup at the wrong hotel could hand attackers your Microsoft 365 session token — no password required.
How to Protect Yourself on the Road
Here's a practical checklist before and during your next trip:
Before you leave:
- Update everything now. Malwarebytes specifically recommends updating your browser, operating system, and important software before you travel. That way, if you see an update prompt on hotel Wi-Fi, you'll know it's fake.
- Enable multi-factor authentication (MFA) on Microsoft 365. Even if attackers steal your password, MFA makes it dramatically harder to access your account. This should be non-negotiable for any business account.
- Set up a VPN with a Kill Switch. A Kill Switch blocks all internet traffic the instant your VPN drops — which prevents attackers from injecting malicious code during the brief unprotected window.
While connected:
- Use your phone's hotspot instead of hotel Wi-Fi. A mobile cellular connection, especially with a reputable carrier, is far safer than an unknown hotel network.
- If you must use hotel Wi-Fi, connect to the captive portal first, then immediately launch your VPN before opening any website or app.
- Never download anything to connect to Wi-Fi. You should never need to install a browser update, certificate, driver, or tool just to log into a hotel network. If you're asked to, disconnect immediately.
- Don't enter Microsoft 365 or work credentials through captive portal redirects. If you need to check corporate email, type the URL directly into your browser rather than clicking through any prompts.
- Inspect SSL certificates on any portal page that asks for more than a room number. Plain HTTP, mismatched hostnames, or untrusted certificate issuers are red flags.
- Be suspicious of urgency. Countdown timers and pressure tactics are a hallmark of ClickFix social engineering.
For organizations:
- Microsoft recommends that organizations "assume that public and hospitality network infrastructure might not be trustworthy" and adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing. Review what information employees provide to hospitality providers when connecting to guest networks.
Getting the Right Setup Before Your Next Trip
VPNs, MFA configuration, and endpoint security aren't complicated to set up — but they do need to be configured correctly to actually protect you. If you're not sure whether your business laptops are properly hardened for travel, we're happy to take a look. Our business IT services include exactly this kind of security review and setup.
The bottom line: hotel Wi-Fi has always carried some risk, but CaptiveCrunch represents a significant escalation — a state-sponsored, AI-assisted operation that's actively compromising shared hospitality network infrastructure at scale. A little preparation before your next trip can be the difference between a routine check-in and handing a Russian intelligence operation the keys to your business.