that hotel wifi login screen you clicked through? it might be russian spies

Microsoft says a Kremlin-linked group has been hijacking hotel and conference Wi-Fi captive portals since May to install espionage malware on…

Aliteq
Ravi Malhotra · Hardware Editor

The short version

Microsoft attributes CaptiveCrunch to Storm-2945, a sub-cluster of Midnight Blizzard (APT29) — the group the US and UK governments tie to Russia's SVR foreign intelligence service.

The short version

Active since at least May 2026; related device-code phishing from the same cluster dates back to February.

The short version

Attackers tamper with DNS and HTTP on hotel and conference captive portals, then serve fake Microsoft 365 logins or fake browser/OS updates.

The short version

Two custom tools do the work: CornFlake, a Go-based RAT with keylogging, webcam and screenshot capture, and ChocoShell, an in-memory PowerShell stealer that pulls Microsoft 365/Azure AD tokens…

The short version

The target is corporate travelers specifically — this is espionage, not commodity credential theft.

My honest take

Treat any hotel or conference Wi-Fi as hostile by default, not just 'less secure.' Use a phone hotspot or a company VPN profile instead of the venue's network for anything that touches real…

Aliteq

Read the full story

that hotel wifi login screen you clicked through? it might be russian spies

Read the full story on Aliteq