Microsoft has warned travellers about CaptiveCrunch, a cyberattack campaign targeting hotel Wi-Fi and other public guest networks worldwide.
The campaign can redirect users to fake security pages, steal account details, and install malware with broad surveillance powers. Microsoft says travellers should treat hotel, airport, conference centre, and other shared networks as untrusted.
Microsoft Threat Intelligence has tracked CaptiveCrunch since early May 2026. The company links the activity to Storm-2945, a sub-group of Midnight Blizzard.
Microsoft describes the operation as ‘widespread but targeted.’ It has found compromised Wi-Fi networks across hospitality venues in several countries. Conference centres have also faced attacks.
The hackers manipulate internet traffic from networks that use captive portals. These portals ask guests to accept terms or enter room details before connecting.
However, compromised equipment lets the attackers control what appears after a traveller joins the network. Microsoft continues to examine how the group first gained access to those systems.
Travellers may see fake browser updates, Windows security checks, or network repair messages after connecting. Some pages also copy Google verification notices.
One observed message says, “Our systems have detected unusual traffic from your computer network.” It then asks the user to complete a security check.
Other prompts imitate Windows Update, Microsoft Defender, DirectX, network diagnostics, document viewers, and browser installers. Users who follow the instructions may download the group’s malware.
Microsoft calls the main remote-access tool CornFlake. Once active, it can record keystrokes, capture screenshots, monitor clipboards, and search USB drives.
The malware can also activate microphones and cameras, collect files, and run remote commands. Moreover, it can steal browser cookies and saved passwords.
Another tool, ChocoShell, targets session cookies, Microsoft 365 sign-in tokens, Wi-Fi credentials, and stored browser passwords. The attackers may use stolen access to enter email, cloud storage, or workplace systems.
Some landing pages also misuse Microsoft’s device-code login process. A victim may enter an attacker-controlled code on a real Microsoft sign-in page. That step can authorize the attacker’s session instead of the traveller’s device.
Microsoft advises travellers to use mobile hotspots or eSIM connections where practical. Users should avoid public Wi-Fi when handling work accounts or sensitive information.
Travellers should never install updates, certificates, security tools, or repair programs offered through a captive portal. They should obtain software updates through official device settings or trusted vendor websites.
Unexpected login pages also require caution. Users should confirm the network name with venue staff and avoid entering corporate passwords into hotel registration pages.
Meanwhile, companies can restrict employee devices from joining networks that administrators have not approved. They can also monitor risky sign-ins and require authentication after unusual activity.
Organizations should limit the employee details shared with hotels and event venues. Such details can include company names, job roles, travel plans, and corporate email addresses.
Anyone who downloaded a suspicious file should disconnect the device and contact their IT or security team. Users should also change exposed passwords from a clean device, revoke active sessions, and review account activity.
A sudden update request after joining public Wi-Fi can serve as a warning sign. So can unfamiliar login domains, copied security alerts, or instructions to run commands manually.
Also Read: Kali365 Phishing Attack Bypasses Microsoft 365 MFA Using Real Login Pages, No Fake Site Needed