Russian APT29 Targets Hotel Wi-Fi Access
Microsoft identifies a state-sponsored campaign exploiting hotel captive portals to deploy infostealers and harvest credentials.
Travelers relying on public wireless networks in hotels and conference centers face a heightened risk of digital compromise following new findings regarding state-sponsored espionage activity. Analysts have identified a campaign in which malicious actors manipulate the infrastructure responsible for managing network access, turning trusted connection portals into distribution points for intrusive software.
Hijacking the Captive Portal Mechanism
The campaign centers on the compromise of captive portal equipment—the networking hardware and software responsible for managing the initial login page users encounter when connecting to public Wi-Fi. Typically, these portals prompt users to input room numbers or accept terms of service to gain internet access.
By seizing control of this management layer, attackers can intercept users at the exact moment they attempt to connect. While the specific methodology for breaching this hardware remains undisclosed by security researchers, the outcome involves redirecting users to fraudulent interfaces rather than the legitimate authentication page.
The Mechanics of the Deception
Once a victim is redirected, the attackers present a variety of decoys designed to facilitate credential theft or malware installation. Among the most common ruses are fake Microsoft 365 login portals that capture user credentials in real-time. In other instances, victims are presented with pages designed to exploit device code phishing, targeting Microsoft Entra ID authentication flows.
Beyond credential harvesting, the hijacked portals are utilized to deliver malicious payloads. Attackers frequently display deceptive browser or operating system update pages, tricking unsuspecting users into initiating a download that installs information-stealing malware directly onto their devices.
Payloads: CornFlake and CocoShell
The investigation highlights two primary malware variants actively distributed through these compromised network portals:
- CornFlake: An infostealer that masks itself as a "Cloud Sync Service" and utilizes multiple persistence mechanisms. It is capable of exfiltrating files, capturing keystrokes and clipboard data, running remote shells, and accessing microphone or webcam hardware.
- CocoShell: A PowerShell-based credential stealer that operates in-memory. Its primary objective is the extraction of browser cookies, stored passwords, Wi-Fi credentials, and active Microsoft 365 or Azure AD tokens.
Attribution to Midnight Blizzard
The activity has been attributed to the threat actor group known as Midnight Blizzard, also designated as APT29. This group is documented as being linked to the Russian Foreign Intelligence Service and maintains a history of targeting high-level government officials and organizations across the West, including previous operations involving SolarWinds.
Implications for Network Security
This operational pivot toward exploiting hospitality-grade networking hardware underscores a significant escalation in how state-sponsored actors reach mobile professionals. By targeting the transit layer of a guest's internet connection, attackers effectively bypass traditional perimeter defenses that a user might have on their local device.
For organizations, this could mean that standard security awareness training regarding public Wi-Fi may no longer be sufficient if the connection gateway itself is effectively weaponized. The ability for these tools to harvest session tokens in addition to passwords suggests that even users with multi-factor authentication could remain vulnerable to unauthorized access if their active tokens are successfully exfiltrated.
Sources
- TechRadar Original source
Continue Reading
Brinks Home Breach Exposes Data Files
The extortion group ShinyHunters has leaked 41 gigabytes of data following a security incident at the Dallas-based home security firm.
INC Ransomware Targets SonicWall Flaws
Threat actors are actively chaining two critical SonicWall vulnerabilities to deploy ransomware and escalate privileges to root.
Coldcard Wallet Firmware Flaw Disclosed
A firmware vulnerability in Coinkite devices has been linked to the loss of over 1,300 Bitcoin in recent address sweeps.