Russian‑linked group targets hotel Wi‑Fi to steal Microsoft 365 tokens

TL;DR Summary
Microsoft ties a global hospitality Wi‑Fi campaign to the Russian group Midnight Blizzard (Storm-2945), detailing DNS tampering and two malware families, CornFlake and ChocoShell, used to steal Microsoft 365 tokens and credentials via phishing, device-code prompts, and fake update pages; researchers urge treating hotel Wi‑Fi as untrusted, using MFA/passkeys, and avoiding corporate credentials on guest networks.
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts BleepingComputer
- Travelers targeted when logging into hotel Wi-Fi networks Malwarebytes
- Microsoft warns hackers have compromised many hotel WiFi networks Mashable
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Microsoft
- Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch iTnews
Reading Insights
Total Reads
1
Unique Readers
17
Time Saved
4 min
vs 5 min read
Condensed
93%
852 → 56 words
Want the full story? Read the original article
Read on BleepingComputer