Tag

Hotel Wifi

All articles tagged with #hotel wifi

CaptiveCrunch Hijacks Hotel Wi‑Fi with Fake Updates, Microsoft Warns
technology2 months ago

CaptiveCrunch Hijacks Hotel Wi‑Fi with Fake Updates, Microsoft Warns

Microsoft warns of a campaign called CaptiveCrunch that compromised hotel Wi‑Fi networks, using fake login and update pop-ups to steal credentials, keystrokes, and even remotely hijack devices, with alleged ties to Russia. To stay safe, travelers should use a private connection (like a mobile hotspot) or be wary of unexpected prompts after connecting to hotel Wi‑Fi.

Hotel Wi-Fi Gateways Weaponized to Steal Microsoft Logins, Microsoft Warns
security2 months ago

Hotel Wi-Fi Gateways Weaponized to Steal Microsoft Logins, Microsoft Warns

Microsoft says a suspected Russian state-backed hacking group hijacked hotel Wi-Fi gateways to redirect travelers to fake Microsoft login pages and secretly deliver malware via ClickFix. The attacks use doppelganger domains mimicking Microsoft online services and have produced variants like Cornflake that impersonate Windows updates or security scans, targeting Windows and Android. ReliaQuest links the activity to APT28, with Microsoft tying it to a Cozy Bear sub-group of APT29. Users should avoid captive portals, rely on cellular data when possible, ignore unexpected prompts, and consider a full-tunnel VPN; attackers likely gained access by abusing weak or known gateway passwords.

Hotels’ Wi‑Fi Gateways Become Phishing Vectors for Microsoft 365 Logins
technology2 months ago

Hotels’ Wi‑Fi Gateways Become Phishing Vectors for Microsoft 365 Logins

Hackers are hijacking hotel and conference Wi‑Fi gateways to redirect business travelers to fake Microsoft 365 sign‑in pages, potentially bypassing MFA via deceptive device prompts and WPAD abuse. Active since at least June, the campaign alters DNS to serve phishing domains (e.g., m365-owa.com, ms365-live.com) and can affect many industries; defenses include using a full‑tunnel VPN, a mobile hotspot, verifying login URLs, avoiding unexpected prompts, updating devices, and having IT disable WPAD where possible.