Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous…
- Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centers
- Victims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malware
- CornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokens
Threat actors are taking over Wi-Fi networks in hotels and conference centers and using the log-in portals to steal credentials and deploy information-stealing malware, experts have claimed.
Researchers from Microsoft have published a new report outlining how they spotted Russian state-sponsored actors, known as Midnight Blizzard or APT29, attacking captive portal equipment - networking hardware and software that manages the login page users see before accessing public Wi-Fi.
When connecting to a hotel network, users are often redirected to a page where they must enter their room number, accept the terms of service, and click “Connect” - that redirection is handled by the captive...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE