www.infosecurity-magazine.com 8/3/2026, 2:51:38 PM · external

APT29 hijacks hotel Wi‑Fi to spy on travelers via fake updates

APT29 hijacks hotel Wi‑Fi to spy on travelers via fake updates
Developing story campaign 4 articles tracked
Russian APT hijacks hotel Wi‑Fi to steal Microsoft 365 tokens
CyberSIXT Evidence Panel
Primary Source microsoft.com
Threat Actor
🇷🇺 UNC2452

A new cyber-espionage campaign named 'CaptiveCrunch', attributed to the Russian hacking group Midnight Blizzard (also known as APT29), targets travelers by hijacking captive portals on hotel and conference Wi-Fi networks. This attack serves fake updates that install Russian espionage malware, specifically a remote access trojan (RAT) named CornFlake. The campaign, ongoing since early May 2026, exploits connectivity checks to deploy malware, posing as legitimate software updates.

Microsoft's investigation revealed vulnerabilities in shared services within the captive portal ecosystem. Recommendations include treating public Wi-Fi as untrustworthy and avoiding installations from captive portals.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline