Hotel Wi-Fi Gateways Weaponized to Steal Microsoft Logins, Microsoft Warns

Microsoft says a suspected Russian state-backed hacking group hijacked hotel Wi-Fi gateways to redirect travelers to fake Microsoft login pages and secretly deliver malware via ClickFix. The attacks use doppelganger domains mimicking Microsoft online services and have produced variants like Cornflake that impersonate Windows updates or security scans, targeting Windows and Android. ReliaQuest links the activity to APT28, with Microsoft tying it to a Cozy Bear sub-group of APT29. Users should avoid captive portals, rely on cellular data when possible, ignore unexpected prompts, and consider a full-tunnel VPN; attackers likely gained access by abusing weak or known gateway passwords.
- Microsoft: Suspected Russian Hackers Are Targeting Logins Via Hotel Wi-Fi PCMag
- Microsoft warns hackers are targeting hotel Wi-Fi networks: What to know, how to protect yourself ABC News - Breaking News, Latest News and Videos
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Microsoft
- Microsoft warns hackers have compromised many hotel WiFi networks Mashable
- Microsoft warns travelers amid hotel Wi-Fi hacks WMUR
Reading Insights
1
3
5 min
vs 6 min read
92%
1,190 → 99 words
Want the full story? Read the original article
Read on PCMag