MALWAREBYTES reported a security threat targeting travelers connecting to hotel Wi-Fi networks, linked to a Russian group named "CaptiveCrunch." The group exploits the routine login process, redirecting user sessions to phishing sites or presenting fake updates that download malware, including a remote access trojan called CornFlake and the fileless infostealer ChocoShell. Signs of the attacks include bogus dialogs resembling legitimate software updates.
Travelers are advised to use personal hot spots, utilize VPNs, inspect certificates, and avoid entering sensitive credentials on potential phishing sites. Staying updated on software can also mitigate risks.