securityaffairs.com 8/1/2026, 3:15:01 PM · external

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

RUSSIAN hackers, part of the Storm-2945 group linked to APT29, have been exploiting hotel Wi-Fi networks to deliver malware and steal Microsoft 365 tokens from travelers since May 2026. The campaign, named CaptiveCrunch, involves manipulating DNS and HTTP traffic on captive portal networks to redirect users to malicious sites.

Key malware includes CornFlake, a Windows remote access trojan that mimics legitimate processes and supports extensive data collection, and ChocoShell, an infostealer targeting Microsoft 365 credentials. Microsoft advises travelers to treat public Wi-Fi as hostile and suggests using mobile hotspots instead.

View full article

Article by CyberSIXT