Microsoft’s hotel Wi-Fi warning concerns a campaign it calls CaptiveCrunch: attackers it links to a Russian espionage operation have manipulated web traffic on hospitality networks to steal account access or install malware on travelers’ devices. Microsoft said on July 31 that it had observed the activity since early May and assessed the operator, Storm-2945, to be a sub-cluster of Midnight Blizzard.
The company described the activity as widespread but targeted, rather than a claim that every hotel guest or hotel network is affected. The Record reported that security firm ReliaQuest had identified affected hospitality organizations in several U.S. cities, India and Saudi Arabia, plus conference centers and other shared venues, and assessed corporate travelers as the main targets.
How does the Microsoft hotel Wi-Fi warning affect travelers?
The networks at issue use captive portals, the web pages guests must access before getting online. Microsoft said Storm-2945 has manipulated DNS and HTTP traffic on networks served by those portals, sending users through infrastructure controlled by the attackers. DNS is the system that translates a web address into the destination a device contacts; altering that routing can send a user somewhere other than the site they intended to reach.
Microsoft observed two paths from that redirection. One sends people to phishing infrastructure, including lookalike domains imitating Microsoft online services. A portion of the operation abused Microsoft Entra ID’s device-code authentication flow, according to Microsoft. The other presents supposed browser or operating-system updates in response to automated browser connectivity checks, then uses ClickFix-style instructions to persuade users to download and run malware.
Microsoft said the phishing can capture credentials and session tokens. The Windows remote-access malware it observed can inventory a system, collect files and keystrokes, take credentials and tokens, monitor removable media, record audio and video, and provide a remote shell to its operators. Those are capabilities Microsoft reported from the malware, not proof that each capability was used against every victim.
What Microsoft knows, and what it does not
Microsoft said its investigation into the initial compromise route for the captive-portal networks is still underway. It found similarities in equipment and management systems across multiple affected networks. That could point to access to shared services in part of the captive-portal ecosystem, Microsoft said, but it does not establish a common provider or rule out separate intrusions.
The attribution also needs the usual threat-intelligence caveat. Microsoft said CaptiveCrunch resembles a DNS-hijacking operation it previously associated with Forest Blizzard, but attributes this campaign to Storm-2945 and Midnight Blizzard. Before Microsoft’s assessment, ReliaQuest said the tactics resembled APT28, also called Forest Blizzard. The Record reported that Western intelligence agencies believe Midnight Blizzard is connected to Russia’s Foreign Intelligence Service.
Microsoft’s disclosure is therefore an account of observed traffic manipulation and malware delivery, plus the company’s attribution assessment. It is not an explanation of how the affected networks were initially breached. Readers can review Microsoft’s technical report on CaptiveCrunch for its detection and mitigation material.
This story draws on original reporting from The Record.