Microsoft Warns of New Hacking Method via Public Wi-Fi in Hotels
Microsoft has issued a warning regarding the emergence of a new cyberattack method targeting users of public Wi-Fi networks in hotels, conference centres, and other public places. In a recent report, the company revealed that perpetrators have successfully taken over captive portal systems, the login pages that typically appear before users can access the internet. This technique is exploited to steal account credentials and spread malware to victims’ devices. According to Microsoft, this attack is linked to the cyber threat group APT29, also known as Midnight Blizzard, a hacking collective widely known to be affiliated with the Russian Foreign Intelligence Service. Rather than creating fake Wi-Fi networks, the attackers infiltrate the hotel’s network management devices so that the login page displayed to users appears completely authentic. When victims attempt to connect to the hotel Wi-Fi, they can be directed to a fake login page resembling a Microsoft 365 service or a device authentication page. In another scenario, victims are even presented with a convincing-looking operating system or browser update notification. When the file is downloaded and executed, the device becomes infected with malware without the user’s knowledge. Microsoft identified two main malware strains used in this campaign: CornFlake and CocoShell. CornFlake is an infostealer malware capable of recording keystrokes, taking screenshots, accessing the microphone and camera, and stealing browser data and important files. Meanwhile, CocoShell is designed to harvest browser cookies, saved passwords, Microsoft 365 and Azure tokens, and Wi-Fi network credentials. The company assesses this method as highly dangerous because it exploits users’ trust in official Wi-Fi networks at hotels or conference centres. Unlike conventional phishing attacks that typically use fake networks, this technique attacks legitimate network infrastructure, making it harder for victims to recognise the threat. To mitigate the risk, Microsoft advises users to avoid downloading software updates that appear after connecting to public Wi-Fi. Users are also encouraged to use a virtual private network (VPN) when accessing public networks, enable multi-factor authentication (MFA), and ensure system updates are performed through the device manufacturer’s official channels, not through pages that appear during Wi-Fi login. Furthermore, whenever possible, users are advised to use personal mobile data networks to access services containing sensitive information, such as internet banking, work email, or corporate accounts. These simple steps can help reduce the risk of data theft when in public places. Microsoft stressed that increased travel activity makes public Wi-Fi networks a prime target for cybercriminals. Therefore, user vigilance remains the first layer of protection to prevent personal information and digital accounts from falling into the hands of irresponsible parties.