Microsoft warns of major Russian hacking campaign targeting public hotel Wi-Fi networks worldwide
Microsoft announced it had identified a large-scale campaign by Russian hackers targeting the public Wi-Fi infrastructure of hotels, conference centers, and other venues worldwide.
The campaign hit hotels and venues that rely on so-called captive portals — the authorization pages that appear when a device connects to a public Wi-Fi network. Microsoft suggested the attackers may have gained access to shared services used by multiple operators of Wi-Fi networks with captive portals.
As part of the campaign, the hackers covertly redirected users to phishing infrastructure under their control and distributed malicious software disguised as browser or operating system updates. The fake update prompts appeared in response to the automatic connectivity checks that browsers run immediately after connecting to a new network.
Microsoft attributes the attack to Storm-2945, a group it has tied to Midnight Blizzard. The company regularly reports on the group’s activity and has linked its members to Russia’s Foreign Intelligence Service. According to Microsoft, Midnight Blizzard hackers were also behind the large-scale 2020 cyberattack on U.S. government agencies through software made by SolarWinds, as well as the 2023 breach of the Outlook email client.
At Meduza, we are committed to transparency about our use of artificial intelligence in the newsroom. The story you’re reading was written by one of our living, breathing journalists and translated from Russian using an AI model configured to follow our strict editorial standards. This translation process is the result of extensive testing and refinements to ensure our English-language coverage is timely and accurate. A Meduza editor reviews every draft before publication.
If you find any errors in this translation, please contact us at [email protected].
To read Meduza’s exclusive content in English, please subscribe to our newsletter.