Hotel Wi-Fi has become the entry point for an active Russian cyberespionage campaign targeting travelers, corporate employees, and the accounts they carry with them. According to Microsoft Threat Intelligence, hackers have been manipulating internet traffic on hospitality networks since early May 2026, redirecting guests toward fake Microsoft sign in pages and malicious software disguised as routine browser or operating system updates.
Microsoft calls the operation CaptiveCrunch and attributes it to Storm 2945, which the company identifies as an operational unit within Midnight Blizzard. The larger group is also known across the cybersecurity industry as APT29, Cozy Bear, the Dukes, and Nobelium.This is not some random crew chasing quick money from stolen credit cards. According to the United Kingdom National Cyber Security Centre, intelligence agencies in the United States, the United Kingdom, Australia, Canada, and New Zealand assess that APT29 almost certainly operates as part of Russia’s Foreign Intelligence Service, known as the SVR.
The same government advisory says the group is known for cyberespionage aimed at governments, think tanks, health care organizations, energy companies, aviation organizations, military institutions, and other targets holding valuable information. Authorities have also connected SVR hackers to the massive 2020 SolarWinds supply chain compromise and operations targeting organizations involved in developing COVID-19 vaccines.
What makes this hotel Wi-Fi campaign especially dangerous is that the victim does not necessarily receive a suspicious email or click a shady advertisement. The hackers are going after the network infrastructure that travelers already expect to use.
Microsoft says its investigation found similarities in the equipment and management systems used across multiple affected hospitality networks. The company has not confirmed exactly how the attackers first gained control, and it has not publicly named any hotel chain, conference venue, network equipment company, or captive portal provider involved.
ReliaQuest researchers assessed with low to medium confidence that attackers may have entered through exposed management systems combined with weak or reused administrator credentials. Once inside a Wi-Fi gateway, the hackers could alter its Domain Name System settings. That process, commonly called DNS poisoning, allows them to redirect internet requests toward servers they control.
To a traveler, everything may still look normal. The device connects to the hotel Wi-Fi. A login or authorization page appears. The page may carry Microsoft branding and resemble a legitimate Microsoft 365 prompt. Behind the scenes, however, the network may be sending the user somewhere entirely different.
ReliaQuest directly observed attackers abusing Microsoft’s device code authentication process. That legitimate process normally allows a person to sign into an account on a device with limited input options. In the attack, the hackers begin their own login session and convince the victim to enter a code on a real Microsoft page. The victim believes they are authorizing their own device, but they are actually approving the attacker’s session.
ReliaQuest said a successful attempt can give the attacker valid Microsoft 365 access tokens while satisfying the account’s multifactor authentication requirement. In other words, a victim can visit a legitimate Microsoft page, correctly complete authentication, and still hand account access to a hacker because the session itself belongs to the attacker.
The hotel Wi-Fi campaign also includes a more aggressive malware route. Microsoft says CaptiveCrunch can redirect users to fake browser updates, Windows repair tools, security scans, or verification pages. Some prompts use a social engineering method called ClickFix, which instructs victims to open a Windows command tool and run code supplied by the page.
One malware program used in the operation is called CornFlake. According to Microsoft, CornFlake is a Windows remote access trojan that can establish a lasting presence on an infected computer. While the malware installs itself, it can display a fake progress window such as “Working on updates… Don’t turn off your computer” to keep the victim from realizing what is happening.
Once active, CornFlake can record keystrokes, monitor copied text, steal browser passwords and session cookies, capture screenshots, access microphones and webcams, search connected USB drives, remove files, and give its operator remote command access. Microsoft says the malware disguises itself as a service called “Cloud Sync Service” and uses several persistence methods designed to restore its access when security software attempts to remove it.
Another tool called ChocoShell focuses on stealing browser sessions, saved passwords, Microsoft 365 sign in tokens, and stored Wi-Fi credentials. Microsoft said evidence inside the code suggests the hackers may have used artificial intelligence assistance during parts of its development.
The campaign has not been limited to one city or country. Microsoft says compromised hospitality networks have been identified in several countries. ReliaQuest reported finding affected gateways across multiple United States cities, along with activity in India and Saudi Arabia. The researchers observed traffic connected to companies in financial services, law, health care, energy, retail, and professional services.
ReliaQuest initially noted that portions of the hotel Wi-Fi activity resembled techniques previously associated with APT28, also known as Fancy Bear or Forest Blizzard. That is a separate Russian military intelligence linked hacking group. ReliaQuest specifically stopped short of directly blaming APT28 because it did not find matching infrastructure, shared code, or another firm technical connection. Microsoft later attributed the wider CaptiveCrunch operation to Storm 2945 within Midnight Blizzard.
Microsoft has not released a confirmed victim count. It has also found indications that Android users could be targeted through pages instructing them to install an application file. The main documented malware, however, has focused heavily on Windows systems and Microsoft cloud accounts.
For travelers, Microsoft recommends treating hotel, airport, conference center, and other guest networks as untrusted. The company advises using cellular data, an eSIM connection, or a personal mobile hotspot when possible. Travelers should never install an update, certificate, security utility, browser repair, or network tool offered through a hotel login page.
Software updates should be opened directly through the trusted settings menu on the device. ReliaQuest also recommends that companies use an always active, full tunnel virtual private network that sends both internet traffic and DNS requests through corporate systems before the hotel gateway can manipulate them.
The danger is not simply that somebody might learn what websites a traveler visited. A compromised hospitality gateway can become the opening move in an intelligence operation that reaches work email, cloud documents, confidential files, stored passwords, cameras, microphones, and entire corporate networks.
