Hotel Wi-Fi Gateways Weaponized to Steal Microsoft Logins, Microsoft Warns

1 min read
Source: PCMag
Hotel Wi-Fi Gateways Weaponized to Steal Microsoft Logins, Microsoft Warns
Photo: PCMag
TL;DR Summary

Microsoft says a suspected Russian state-backed hacking group hijacked hotel Wi-Fi gateways to redirect travelers to fake Microsoft login pages and secretly deliver malware via ClickFix. The attacks use doppelganger domains mimicking Microsoft online services and have produced variants like Cornflake that impersonate Windows updates or security scans, targeting Windows and Android. ReliaQuest links the activity to APT28, with Microsoft tying it to a Cozy Bear sub-group of APT29. Users should avoid captive portals, rely on cellular data when possible, ignore unexpected prompts, and consider a full-tunnel VPN; attackers likely gained access by abusing weak or known gateway passwords.

Share this article

Reading Insights

Total Reads

1

Unique Readers

3

Time Saved

5 min

vs 6 min read

Condensed

92%

1,19099 words

Want the full story? Read the original article

Read on PCMag