Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware

Wait 5 sec.

Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centersVictims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malwareCornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokensThreat actors are taking over Wi-Fi networks in hotels and conference centers and using the log-in portals to steal credentials and deploy information-stealing malware, experts have claimed.Researchers from Microsoft have published a new report outlining how they spotted Russian state-sponsored actors, known as Midnight Blizzard or APT29, attacking captive portal equipment - networking hardware and software that manages the login page users see before accessing public Wi-Fi. When connecting to a hotel network, users are often redirected to a page where they must enter their room number, accept the terms of service, and click “Connect” - that redirection is handled by the captive portal.CornFlake and CocoShellMicrosoft did not explain exactly how this gear is attacked. However, when users try to log in on compromised networks, they may be redirected to a fake Microsoft 365 login portal that steals their credentials. They may also be redirected to device code phishing pages abusing Microsoft Entra ID authentication flows. Finally, the researchers also saw the captive portals being used to display fake browser and OS update pages that trick victims into downloading infostealers.So far, MIcrosoft found two malware variants being distributed: CornFlake, and CocoShell. CornFlake acts as an infostealer capable of grabbing keystrokes and clipboard, running remote shell access, grabbing screenshots, using the microphone and the webcam, stealing browser credentials and cookies, exfiltrating files, and more. It presents itself as a “Cloud Sync Service” while using multiple persistence mechanisms.CocoShell, on the other hand, is an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.APT29 is one of the most documented state-sponsored threat actors out there. It’s been active for years and is well-known for its links to Russia’s Foreign Intelligence Service and notable attacks on high-ranking western targets, such as US and German Government officials, as well as SolarWinds and Microsoft.