Microsoft Warns Travelers Against Hotel Wi-Fi Over Password Theft and Spying Risks

2 mins read

Microsoft’s security team has issued what comes next warning to travelers about the risk of connecting to the Wi-Fi networks in hotels and other public guest networks. CaptiveCrunch, a complex attack campaign, has been targeting hospitality networks since at least early May, enabling attackers to extract passwords, deploy malware and even remotely capture audio, video and keystrokes.

We have seen the operation tied to the group that Microsoft has identified as Storm-2945, which is part of the larger Russian sharing actor Midnight Blizzard, associate with this operation. The would-be cyber criminals will typically look to attack the captive portals that are often found within many hotels, conference centers and other such venues to allow internet access to their patrons, and then when the network goes live, the network users could be silently redirected or spoofed with fake prompts.

Sometimes they are presented with convincing Windows login pages or prompted to input a device code on what seems to be a legitimate sign-in page. Inputting this information could provide access to their email and One Drive, and in some instances corporate resources. In the second group of examples, they are prompted with extra Windows updates, Browser fixes, Troubleshooting tools to improve network connectivity and Installers for other applications, but click are downloaded malware.

Of the duo, there are two strains that are noteworthy. The first, called CornFlake, is a remote access trojan (RAT). It has the ability to exfiltrate files and passwords, log keystrokes, take screenshots, and turn on a device’s webcam and microphone in order spy on the user. The second is called ChocoShell. Unlike CornFlake, ChocoShell’s capabilities are targeted at stealing browser cookies, passwords that have been saved, Microsoft 365 sessions, with passwords stored for wireless networks. Both programs provide an intruder almost complete control over an infected device. Microsoft is monitoring activity in several countries and points out that this activity does not seem limited to a handful of properties.

The company points out that hospitality-industry-related organizations and other networks that use captive portal hardware have been targeted. Because the fake messages show up in the same browser window or flow guests see when they connect to hotel Wi-Fi, most aren’t aware of anything until after the damage occurs. How do Microsoft advise we should act? Quite simply – don’t trust anything claiming to be a hotel, conference or airport or other guest wireless network.

Use a dedicated mobile hotspot, an eSIM data connection or other private network wherever practical. When connecting via public Wi-Fi, do not allow any new software, certificates or updates to be downloaded, nor should anyone accept any new device-code flows received from the captive portal or in-system popups. But, there is still much we can do to reduce risk.

Enable strong authentication methods (e.g. MFA) and like the client or the user authentication cannot be delegated to another device, reduce the flow to provide less device-code flows. For the business traveler the risk is even greater. Corporate email access and cloud file access could bring entry into larger networks, and personal email accounts could reveal financial information, private correspondence, and stored passwords. A non-business traveler could still end up with a device that is listening in or collecting data without realizing it.

NY DAILY INSIDER

Nydailyinsider is a seasoned journalist with over 15 years of experience in the industry. They have written for several high-profile publications, including Variety, The Hollywood Reporter, and Entertainment Weekly. Nydailyinsider has covered a wide range of topics, from celebrity profiles and movie reviews to industry trends and analysis. They are known for their insightful commentary and thoughtful writing style. In addition to their work as a writer, they are also a frequent guest on entertainment news shows and podcasts. They holds a degree in Journalism from New York University and currently resides in Los Angeles with their family.

Leave a Reply

Your email address will not be published.

Latest from NY DAILY INSIDER