Connecting to hotel Wi-Fi could lead to data hacking! Microsoft issues a warning
Microsoft Alert: Fraudsters have targeted this specific system in the attack. Notably, in some instances, attackers can manipulate the network’s DNS and HTTP traffic to suit their objectives.
Microsoft Alert: The internet has become a necessity for people. It is common for travelers to use the free Wi-Fi available at hotels. However, in today’s technological landscape, cybercriminals have become increasingly sophisticated, employing novel methods to defraud people. In light of this, Microsoft has issued an important warning for hotel guests.
Microsoft’s Warning
According to media reports, Microsoft revealed details of a cyber-attack campaign named “CaptiveCrunch” in a report released on July 31. The company states that cyber attackers are compromising the sign-in systems of Wi-Fi networks at hotels and conference centers. Consequently, users connecting to the network are presented with fake software updates and fraudulent login pages.
Targeting Hotel Wi-Fi Sign-in Pages
Typically, when you connect to a hotel’s Wi-Fi network for the first time, you are greeted by a login page requiring you to accept the terms and conditions. This interface is known as a “Captive Portal.”
Microsoft reports that fraudsters have specifically targeted this system. In some cases, attackers can alter the network’s DNS and HTTP traffic. This means that instead of accessing the intended website or page, the user can be redirected to a different site or page controlled by the attackers.
Fraud via Fake Microsoft Login Pages
Attackers also employ methods to steal users’ login credentials and session data. To achieve this, they present users with a Microsoft sign-in page that appears completely authentic.
Since July 16, Microsoft has also observed pages that redirect users to a “Device Code Authentication” process. This is a legitimate Microsoft login feature, but attackers are misusing it.
The most dangerous aspect is that the Microsoft website where the user enters the code is completely genuine; however, the code itself was initiated by the attacker. This makes this attack method appear more sophisticated than others.
AI is also being utilized
According to Microsoft, the group ‘Storm-2945’ has been using AI in its cyber operations since February. This involves technologies such as Device Code and OAuth-based phishing.
The company states that AI played a key role in the group’s activities, although Microsoft did not specify which AI systems were used or which tasks were automated.
What happens after the malware is installed?
If a user runs the software or executes the commands specified by the attacker, their data could be compromised. Microsoft notes that attackers can perform various activities on an infected device, such as:
Recording keystrokes
Taking screenshots
Recording audio and video
Stealing browser cookies
Accessing saved passwords
Monitoring USB drive activity
Executing remote commands via PowerShell or Command Prompt
Routing internet traffic through an attacker-controlled proxy
Consequently, attackers are not limited to just the single device; they can also gain access to linked accounts and other sensitive information.
Android users should also be cautious
It is worth noting that this threat is not limited to Windows users; Android users can also be affected. Some ‘ClickFix’ pages prompt Android users to download and install APK files from external sources. However, according to Microsoft, the tools targeting Android are currently less active compared to those targeting Windows.
Precautions when using hotel Wi-Fi
Hotel Wi-Fi networks have become easy targets for cybercriminals. Therefore, it is important to keep certain precautions in mind to protect yourself from cyberattacks while staying at a hotel. Use a personal mobile hotspot whenever possible. This significantly reduces the risk posed by attackers connected to the hotel’s Wi-Fi network.
Additionally, if using guest Wi-Fi is necessary, using a VPN is a better option. Also, do not accept any unknown downloads or installations that appear on the Wi-Fi captive portal.

