Skip to content

Microsoft flags renewed attacks on hospitality Wi-Fi networks

Compromised Wi-Fi login pages redirect victims to infrastructure controlled by Russia-linked attackers.

Microsoft flags renewed attacks on hospitality Wi-Fi networks
Image Credit: https://unsplash.com/@bernardhermant

A hacking campaign targeting the hospitality sector through hijacked network login pages and abuse of Microsoft Entra ID is showing fresh activity, two months after Microsoft first flagged the attacks.

The CaptiveCrunch campaign attributed to Storm-2945, a sub-cluster of the Russia-linked Midnight Blizzard group, was seen using “manipulated network traffic and captive portals” in attacks on 29 September.

In a blog post update, Microsoft Threat Intelligence (MTI) added that the activity was consistent with reports from Lumen research arm Black Lotus Labs and said: “Storm-2945’s continued access to these upstream providers has likely enabled this rapid re-deployment.”

MTI’s initial warning in July said the campaign used domains mimicking Microsoft online services for phishing operations that “abuse the device-code authentication flow in Microsoft Entra ID.”

Portals and Entra ID

This content is for members only

Subscribe
Add The Stack on Google