{
    "success": true,
    "data": {
        "id": 1904906,
        "msgid": "microsoft-warns-of-new-hacking-method-via-public-wi-fi-in-hotels-1786031476",
        "date": "2026-08-06 22:20:00",
        "title": "Microsoft Warns of New Hacking Method via Public Wi-Fi in Hotels",
        "author": "Reynaldi Andrian Pamungkas",
        "source": "MEDIA_INDONESIA",
        "tags": "",
        "topic": "Technology",
        "summary": "Microsoft has issued a warning about a sophisticated new cyberattack campaign targeting public Wi-Fi networks in hotels and conference centres. The threat group, linked to Russian foreign intelligence, compromises legitimate network hardware to present fake login pages that steal credentials and distribute malware. Users are advised to use VPNs, enable multi-factor authentication, and avoid downloading updates prompted by public Wi-Fi connections.",
        "content": "<p>Microsoft has issued a warning regarding the emergence of a new\ncyberattack method targeting users of public Wi-Fi networks in hotels,\nconference centres, and other public places. In a recent report, the\ncompany revealed that perpetrators have successfully taken over captive\nportal systems, the login pages that typically appear before users can\naccess the internet. This technique is exploited to steal account\ncredentials and spread malware to victims\u2019 devices. According to\nMicrosoft, this attack is linked to the cyber threat group APT29, also\nknown as Midnight Blizzard, a hacking collective widely known to be\naffiliated with the Russian Foreign Intelligence Service. Rather than\ncreating fake Wi-Fi networks, the attackers infiltrate the hotel\u2019s\nnetwork management devices so that the login page displayed to users\nappears completely authentic. When victims attempt to connect to the\nhotel Wi-Fi, they can be directed to a fake login page resembling a\nMicrosoft 365 service or a device authentication page. In another\nscenario, victims are even presented with a convincing-looking operating\nsystem or browser update notification. When the file is downloaded and\nexecuted, the device becomes infected with malware without the user\u2019s\nknowledge. Microsoft identified two main malware strains used in this\ncampaign: CornFlake and CocoShell. CornFlake is an infostealer malware\ncapable of recording keystrokes, taking screenshots, accessing the\nmicrophone and camera, and stealing browser data and important files.\nMeanwhile, CocoShell is designed to harvest browser cookies, saved\npasswords, Microsoft 365 and Azure tokens, and Wi-Fi network\ncredentials. The company assesses this method as highly dangerous\nbecause it exploits users\u2019 trust in official Wi-Fi networks at hotels or\nconference centres. Unlike conventional phishing attacks that typically\nuse fake networks, this technique attacks legitimate network\ninfrastructure, making it harder for victims to recognise the threat. To\nmitigate the risk, Microsoft advises users to avoid downloading software\nupdates that appear after connecting to public Wi-Fi. Users are also\nencouraged to use a virtual private network (VPN) when accessing public\nnetworks, enable multi-factor authentication (MFA), and ensure system\nupdates are performed through the device manufacturer\u2019s official\nchannels, not through pages that appear during Wi-Fi login. Furthermore,\nwhenever possible, users are advised to use personal mobile data\nnetworks to access services containing sensitive information, such as\ninternet banking, work email, or corporate accounts. These simple steps\ncan help reduce the risk of data theft when in public places. Microsoft\nstressed that increased travel activity makes public Wi-Fi networks a\nprime target for cybercriminals. Therefore, user vigilance remains the\nfirst layer of protection to prevent personal information and digital\naccounts from falling into the hands of irresponsible parties.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/microsoft-warns-of-new-hacking-method-via-public-wi-fi-in-hotels-1786031476",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}