Endpoint/Device Security, Threat Intelligence

Russia-linked Midnight Blizzard targets hotel Wi-Fi networks in US, Europe

Man holding smartphone with wi-fi sign. Internet, Technology

Microsoft Threat Intelligence reported that the Russia-linked threat actor Midnight Blizzard is targeting Wi-Fi networks in the hotel and hospitality sector.

In a July 31 blog post, Microsoft dubbed the campaign "CaptiveCrunch" because the threat actor conducted traffic manipulation attacks that are served by captive portals primarily operating in the United States and Europe.

The case first came to light on July 23 when ReliaQuest reported that a portion of the attacks leverage doppelganger domains that mimic Microsoft 365. The aim is to conduct adversary-in-the-middle phishing attacks that abuse the authentication services in Microsoft EntraID to ultimately drop malware.

Kern Smith, vice president of global solutions at Zimperium, said this campaign demonstrated how attackers continue to shift away from traditional email-based phishing attacks and instead target the point where users establish trust.

“Business travelers expect hotel Wi-Fi login pages to be legitimate, making captive portals an ideal environment for credential theft and malware delivery,” said Smith.

Microsoft's research said that attackers may also be directing Android users to download malicious APK files. Smith added that once users are convinced to install software outside of trusted app stores, attackers can gain persistent access to the device, harvest credentials, intercept communications, or monitor user activity long after they leave the hotel.

“Organizations should remind employees that connecting to public Wi-Fi should never require downloading applications, installing certificates, or responding to unexpected Microsoft authentication prompts,” said Smith. “Employees should use trusted VPN connections whenever possible, avoid sideloading applications, and verify any authentication request through official applications rather than browser pop-ups.”

Rogier Fischer, co-founder and CEO at Hadrian, added that public Wi-Fi has never really been considered a trusted network, but this campaign shows that attackers are actively targeting them as a weak point.

“In many ways it’s ideal an vector to target,” said Fischer. “Business travel creates a unique concentration of privileged users outside their normal security environment. Historically, attackers have targeted the destination, in this case M365, with their campaigns. But as those have become hardened, they have shifted focus to other weak links. When travelling, use phishing-resistant authentication, such as MFA, and avoid unexpected login prompts and software updates.”

Gary Orenstein, chief customer officer at Bitwarden, said business travelers should treat any unexpected corporate sign-in, MFA, device code, or software update prompt that appears after joining hotel or conference WiFi as a potential security incident.

Orenstein said a legitimate captive portal may ask users to accept terms or enter a venue-provided access code, but it should not request corporate credentials, MFA approval, a Microsoft device code, or a browser or operating system update.

“If one appears, business users should disconnect, switch to cellular service or a trusted hotspot, notify the security team, and access the service directly through its official app or website,” said Orenstein. “Initiate updates independently through device or application settings, or an official app store.”

Orenstein said security teams should establish the following travel controls in advance:

  • Prefer company-provided or approved cellular connectivity over guest WiFi.
  • Update managed devices before departure.
  • Configure an always-on, full tunnel VPN that blocks internet access until the protected tunnel is established.
  • Use phishing-resistant authentication such as passkeys or FIDO2 security keys, and disable device code authentication unless required for a documented workflow.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds