www.malwarebytes.com 8/4/2026, 12:31:34 PM · external

Russian Hackers Hijack Hotel WiFi to Infect Travellers

Russian Hackers Hijack Hotel WiFi to Infect Travellers
Developing story campaign 5 articles tracked
Russian APT hijacks hotel Wi‑Fi to steal Microsoft 365 tokens
CyberSIXT Evidence Panel
Primary Source microsoft.com
Threat Actor
CaptiveCrunch

MALWAREBYTES reported a security threat targeting travelers connecting to hotel Wi-Fi networks, linked to a Russian group named "CaptiveCrunch." The group exploits the routine login process, redirecting user sessions to phishing sites or presenting fake updates that download malware, including a remote access trojan called CornFlake and the fileless infostealer ChocoShell. Signs of the attacks include bogus dialogs resembling legitimate software updates.

Travelers are advised to use personal hot spots, utilize VPNs, inspect certificates, and avoid entering sensitive credentials on potential phishing sites. Staying updated on software can also mitigate risks.

View Primary Source Via www.malwarebytes.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline