Microsoft warns hackers target hotel Wi-Fi networks

Microsoft is warning travelers about a new cyber threat aimed at hospitality venues in what it described as “widespread but targeted” internet traffic manipulation attacks.

Microsoft Threat Intelligence posted a warning on its website Friday about an internet hijacking operation dubbed “CaptiveCrunch.” The company attributed the campaign to Russian state-sponsored hackers Storm-2945, a “sub-cluster” of the cyber group Midnight Blizzard, also known as “APT29” and “Cozy Bear.”

Microsoft said Midnight Blizzard has been linked to the Russian Foreign Intelligence Service, or SVR.

The company said it identified “widespread compromise of Wi-Fi networks at hospitality-related organizations,” among other networks.

Microsoft also shared details on the threat, how the group carried out the hijacking and recommended practices for the public to avoid being compromised.

How does the hotel internet hack work?

Storm-2945 has targeted hotels and other hospitality venues worldwide, affecting those who connect to Wi-Fi networks with guest logins, known as captive portals, according to Microsoft.

Users are then prompted to download malicious files. The hijackers infect the user’s device with malware that harvests browser cookies, passwords, documents and other data, Microsoft said. The hackers can also capture keystrokes, screenshots, audio and video, monitor the clipboard and operate the device remotely.

In some instances, users attempting to access a compromised network may be redirected to fake login screens. At that point, the hijackers can access the user’s Microsoft 365 account, granting them further access to the person’s email and OneDrive.

What does the hack look like?

Users who encounter the threat may see a variety of false windows designed to disguise the scam, according to Microsoft.

The tech giant listed several potential fake windows that may appear upon logging into a compromised network, prompting users to download updates or patches. They include:

  • “winupdate”: A Windows Update screen displaying the words “Working on updates Don’t turn off your computer”
  • “defender”: A fake Windows Security virus scan
  • “directx”: A “DirectX End-User Runtime Web Installer”
  • “vcredist”: A Microsoft Visual C++ 2015-2022 Redistributable installer
  • “sysopt”: A disk optimization utility
  • “netfix”: A false Windows Network Diagnostics tool
  • “browser”: A browser update prompt
  • “pdfview”: A document viewer installer

In other cases, users may be prompted to update their browser “in response to automated connectivity checks,” according to Microsoft.

These false “connectivity checks” may resemble Google browser screens reading “Verify it’s you,” and “Our systems have detected unusual traffic from your computer network. Please complete the security check to access Google Search.” Following the prompts allows the hijackers to gain access to a user’s device and operate it remotely.

How can users protect themselves from being hacked?

Microsoft advised users to exercise caution when using guest networks at hotels, conferences, airports or other public venues.

The company recommended users rely on private connectivity, such as phone hotspots, rather than public options whenever possible.

Microsoft also urged the public to use caution when faced with pop-up requests and to avoid “downloading software updates, certificates, browser updates, network troubleshooting tools, or security utilities presented through captive portals or other unexpected web prompts.”

Microsoft also warned organizations to “review what information employees provide to hospitality providers when connecting to guest networks.”

Leave a Comment