Russian state-sponsored hackers have been hijacking public Wi-Fi networks at hotels and conference centers worldwide, using artificial intelligence (AI) to power much of the operation.Microsoft Threat Intelligence reported the campaign, named CaptiveCrunch, on July 31, attributing it to a group tracked as Storm-2945. The company said the campaign has been operating since early May, with the goal of stealing login credentials from corporate and government business travelers.JOIN US ON TELEGRAMFollow our coverage of the war on the @Kyivpost_official.The group is reportedly an operational sub-cluster of Midnight Blizzard – a threat actor the US and UK governments have linked to Russia’s Foreign Intelligence Service (SVR).“Midnight Blizzard is consistent and persistent in their operational targeting, and their objectives rarely change,” Microsoft reported, adding that “their focus is to collect intelligence through longstanding and dedicated espionage in support of Russian foreign policy interests.”How the attack worksThe hackers reportedly exploited the equipment and management systems behind hotel Wi-Fi registration pages, known as captive portals.They then manipulated the domain name system (DNS) and hypertext transfer protocol (HTTP) traffic to redirect guests through infrastructure under their control.According to Microsoft, this technique shares some similarities with a separate DNS hijacking operation reported in April.Once redirected, victims received fake update prompts disguised as routine browser or operating system checks. When clicked, these prompts delivered malware, including a Windows remote access trojan called CornFlake, capable of logging keystrokes, stealing credentials and session tokens, as well as conducting audio and video surveillance on infected devices. Other Topics of Interest Putin Replaces Key Ukraine Commanders as Russia’s Donbas Offensive Slows Putin appointed new commanders to lead key Russian formations fighting in Ukraine as Moscow’s territorial gains slowed and its plans to seize the entire Donbas faced further delays. Microsoft said the investigation into how the captive portal networks were initially breached is ongoing.However, the company noted that shared equipment and management systems across multiple affected venues suggest the intrusions may stem from a common point of access, rather than isolated compromises.A pattern of targeting Western institutionsMicrosoft’s report ties the CaptiveCrunch campaign to Midnight Blizzard’s long-standing focus on specific categories of victims.“This threat actor is known to primarily target governments, diplomatic entities, non-governmental organizations (NGOs), and information technology (IT) service providers, primarily in the US and Europe,” Microsoft reported.According to the company, the group rarely deviates from this pattern and has a lengthy record of targeting Western institutions.On July 25, CNN reported that Russian state-backed hackers had targeted US nuclear scientists, defense contractors and government employees in a cyber-espionage campaign using techniques first deployed against Ukraine.US cybersecurity company Proofpoint found that the hackers were particularly interested in “entities and users with an interest in nuclear fusion,” suggesting Moscow may have been seeking insight into advances made by competitors in the field.The campaign also targeted federal and local government agencies, law enforcement, education, energy, media, technology organizations and the defense industry.Authorities widely believe these types of cyberattacks have been happening since at least July 2025.EU blacklists Russian nationals and companies over cyberattacksOn July 14, the EU and the UK imposed coordinated sanctions targeting Russia‘s cyber operations, accusing Moscow’s Federal Security Service (FSB) of orchestrating a campaign of cyberattacks against European governments, critical infrastructure, and businesses.The sanctions also targeted nine individuals and companies accused of being a part of Russia’s “cyber ecosystem,” which is responsible for phishing campaigns and ransomware.The measures marked the first time the EU and the UK had simultaneously imposed sanctions under their respective sanctions regimes.According to United24Media, the UK, US, and Australia imposed new sanctions on Oct. 1, 2024 on members of the Russian cybercriminal group named “Evil Corp,” which has caused significant damage in over 40 countries using Dridex malware.The European Commission has finalized its 21st sanctions package against Russia on July 26, tightening restrictions on the Russian financial sector and freezing the price cap on crude oil exports at $44 per barrel. Kyiv Post is Ukraine’s first and oldest English news organization, reporting since 1995. Its international reach – 97% of readers are outside of Ukraine – make it truly Ukraine’s global voice.
Russian State Hackers Target Hotel Wi-fi to Spy on Travelers, Microsoft Reports
Full Article
Original Source
Read the full article at Kyivpost →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.