Breaking
Cyber CrimeDeveloping Story

Russian APT29 Targets Hotel Wi-Fi Access

Microsoft identifies a state-sponsored campaign exploiting hotel captive portals to deploy infostealers and harvest credentials.

··2 hours ago·2 min read
hotel lobby wifi network security
Photo by Picsum Photos on Unsplash

Travelers relying on public wireless networks in hotels and conference centers face a heightened risk of digital compromise following new findings regarding state-sponsored espionage activity. Analysts have identified a campaign in which malicious actors manipulate the infrastructure responsible for managing network access, turning trusted connection portals into distribution points for intrusive software.

Hijacking the Captive Portal Mechanism

The campaign centers on the compromise of captive portal equipment—the networking hardware and software responsible for managing the initial login page users encounter when connecting to public Wi-Fi. Typically, these portals prompt users to input room numbers or accept terms of service to gain internet access.

By seizing control of this management layer, attackers can intercept users at the exact moment they attempt to connect. While the specific methodology for breaching this hardware remains undisclosed by security researchers, the outcome involves redirecting users to fraudulent interfaces rather than the legitimate authentication page.

The Mechanics of the Deception

Once a victim is redirected, the attackers present a variety of decoys designed to facilitate credential theft or malware installation. Among the most common ruses are fake Microsoft 365 login portals that capture user credentials in real-time. In other instances, victims are presented with pages designed to exploit device code phishing, targeting Microsoft Entra ID authentication flows.

Beyond credential harvesting, the hijacked portals are utilized to deliver malicious payloads. Attackers frequently display deceptive browser or operating system update pages, tricking unsuspecting users into initiating a download that installs information-stealing malware directly onto their devices.

Payloads: CornFlake and CocoShell

The investigation highlights two primary malware variants actively distributed through these compromised network portals:

  • CornFlake: An infostealer that masks itself as a "Cloud Sync Service" and utilizes multiple persistence mechanisms. It is capable of exfiltrating files, capturing keystrokes and clipboard data, running remote shells, and accessing microphone or webcam hardware.
  • CocoShell: A PowerShell-based credential stealer that operates in-memory. Its primary objective is the extraction of browser cookies, stored passwords, Wi-Fi credentials, and active Microsoft 365 or Azure AD tokens.

Attribution to Midnight Blizzard

The activity has been attributed to the threat actor group known as Midnight Blizzard, also designated as APT29. This group is documented as being linked to the Russian Foreign Intelligence Service and maintains a history of targeting high-level government officials and organizations across the West, including previous operations involving SolarWinds.

Implications for Network Security

This operational pivot toward exploiting hospitality-grade networking hardware underscores a significant escalation in how state-sponsored actors reach mobile professionals. By targeting the transit layer of a guest's internet connection, attackers effectively bypass traditional perimeter defenses that a user might have on their local device.

For organizations, this could mean that standard security awareness training regarding public Wi-Fi may no longer be sufficient if the connection gateway itself is effectively weaponized. The ability for these tools to harvest session tokens in addition to passwords suggests that even users with multi-factor authentication could remain vulnerable to unauthorized access if their active tokens are successfully exfiltrated.

#apt29#malware#wi-fi#cybersecurity#infostealer

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted with AI assistance from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our AI Policy →

← Back to all stories