A new cyber espionage campaign targeting business travelers and government officials has been identified through attacks on public Wi-Fi networks in hotels and conference centers worldwide. According to a report from Microsoft Threat Intelligence, the operation, dubbed "CaptiveCrunch," began in May and is linked to the hacking group Storm-2945.
Link to Russian Intelligence Services
Storm-2945 is an operational sub-cluster of Midnight Blizzard – a threat that the US and UK governments link to the Russian Foreign Intelligence Service (SVR). Microsoft points out that Midnight Blizzard is characterized by long-term espionage activity and persistence in its goals, which focus on gathering information to support Russian foreign policy interests.
Attack Mechanism
The malicious actors have exploited vulnerabilities in the management systems of hotel Wi-Fi login pages, known as "captive portals." By manipulating the Domain Name System (DNS) and HTTP protocol traffic, the hackers redirect users to infrastructure that they control themselves. This tactic resembles a similar DNS hijacking operation reported in April.
Malware and Consequences
After being redirected, victims receive fake notifications for browser or operating system updates. Upon clicking them, a Windows Trojan called "CornFlake" is installed. This software possesses extensive spying capabilities: keylogging, theft of login credentials and session tokens, as well as remote audio and video surveillance of infected devices.
You may also like
- Italian media report neo-Nazi group attack against Jewish youths in a Sofia hotel
- The Ceuta Crisis: Spain Accuses International Forces of Spreading Disinformation
- AI Towers for Early Fire Detection: Construction of Monitoring System in Rila Begins
- Zelensky Appoints Rustem Umerov as Chief Negotiator for Ending the War with Russia
Microsoft's investigation is ongoing, with the company noting that the use of shared equipment and management systems in many affected locations suggests that the breaches likely originate from a common point of access.