Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flaws in Google Cloud AI Let Attackers Hijack CI/CD Pipelines
August 4, 2026
BINDCLOAK Malware Exploits Windows to Elevate Privileges, Steal Tokens
August 4, 2026
Fake AI Tools Deliver Malware to Developers, Granting Enterprise Access
August 4, 2026
Home/Threats/Midnight Blizzard Hacks Hotel Wi-Fi to Steal Cloud Credentials From Travelers
Threats

Midnight Blizzard Hacks Hotel Wi-Fi to Steal Cloud Credentials From Travelers

Key Takeaways A sophisticated campaign, dubbed “CaptiveCrunch” by Microsoft, is leveraging compromised hotel Wi-Fi networks to target travelers globally. The Russia-linked threat group...

Jennifer sherman
Jennifer sherman
August 4, 2026 4 Min Read
3 0

Key Takeaways

  • A sophisticated campaign, dubbed “CaptiveCrunch” by Microsoft, is leveraging compromised hotel Wi-Fi networks to target travelers globally.
  • The Russia-linked threat group Midnight Blizzard is behind the operation, aiming to steal cloud credentials and deliver malware.
  • Attackers manipulate Wi-Fi captive portals and DNS responses, redirecting victims to malicious pages disguised as legitimate login or software update prompts.
  • The campaign exploits the trusted nature of public Wi-Fi access, making it particularly effective against business travelers.
  • Strong mitigation strategies include using a full-tunnel VPN, disabling WPAD, and exercising extreme caution with any prompts on public networks.

Midnight Blizzard Exploits Hotel Wi-Fi to Steal Cloud Credentials in Global Campaign

A new, highly concerning threat has emerged for individuals connecting to hotel Wi-Fi networks worldwide. The Russia-backed advanced persistent threat (APT) group known as Midnight Blizzard is actively exploiting these networks in a campaign that Microsoft has designated “CaptiveCrunch.” This operation focuses on compromising the trusted login pages of hotels, conference venues, and other public Wi-Fi providers to target unsuspecting business travelers, ultimately aiming for malware delivery and the theft of cloud credentials.

Table Of Content

  • Key Takeaways
  • Midnight Blizzard Exploits Hotel Wi-Fi to Steal Cloud Credentials in Global Campaign
  • How Midnight Blizzard Hijacks Hotel Wi-Fi
  • Cloud Accounts: The Ultimate Prize
  • What You Should Do

Unlike traditional phishing attacks that rely on suspicious emails, this campaign directly interferes with the network connection itself. Victims are seamlessly rerouted through a malicious Wi-Fi sign-in process, encountering prompts that mimic routine software updates or legitimate cloud account login pages. This approach capitalizes on a moment when users often lower their guard, making the familiar network login screen an exceptionally effective lure.

Microsoft said in a report that the global scope of this operation is significant, leveraging the inherent trust users place in public network infrastructure. Travelers frequently prioritize quick Wi-Fi access before meetings or when mobile data is scarce, creating an opportune environment for attackers to exploit.

How Midnight Blizzard Hijacks Hotel Wi-Fi

The core of the CaptiveCrunch campaign involves Midnight Blizzard compromising or interfering with the underlying Wi-Fi gateway infrastructure that governs captive portals. These portals are the initial web pages users encounter before gaining full internet access on public networks. By manipulating DNS responses, the attackers can divert a traveler’s browser to malicious infrastructure they control, rather than the intended, legitimate captive portal.

The altered portal can convincingly imitate a standard Wi-Fi access page. However, it may also push deceptive browser update prompts or system alerts. Should a user accept such a prompt, it triggers malware delivery, establishing an initial foothold on the device. This allows the attackers to exfiltrate data, monitor activity, or prepare the device for more extensive compromise.

This technique offers a significant advantage over conventional phishing, as the malicious request appears precisely when a user is actively attempting to connect online and expects to interact with network authentication. Previous reports on compromised Wi-Fi gateways have similarly highlighted that a single manipulated gateway can redirect every connected device toward credential-harvesting pages.

Furthermore, the attackers exploit the Web Proxy Auto-Discovery Protocol (WPAD) to influence how a device routes its web traffic. This can expose authentication activities that users believe are secure, particularly when corporate devices are configured to automatically seek network proxy settings.

The utilization of public network infrastructure in this manner signifies a strategic evolution by threat actors beyond traditional inbox-based social engineering. While Midnight Blizzard has previously employed tactics like Teams chat credential theft, CaptiveCrunch positions the attacker closer to the victim’s device by exploiting a network that the victim has explicitly chosen to trust.

Cloud Accounts: The Ultimate Prize

The ultimate objective of the CaptiveCrunch campaign is to gain unauthorized access to cloud accounts. A single stolen login can provide attackers with extensive access to emails, files, business applications, and critical identity data. Attackers may harvest passwords, session tokens, or device authorization information, enabling them to access services without requiring the victim’s physical device for subsequent logins.

This risk is particularly acute for organizations heavily reliant on cloud identity systems to support remote workforces. A compromised account can be used to access sensitive information, impersonate an employee, send internal communications, or serve as a beachhead for a larger organizational intrusion.

This activity aligns with broader concerns surrounding adversary-in-the-middle (AiTM) phishing attacks, where criminals intercept authentication traffic in an attempt to bypass common security controls. While multi-factor authentication (MFA) remains crucial, organizations should not assume it provides absolute protection against all token or session theft attempts. Microsoft strongly advises treating hotel and other public Wi-Fi networks as inherently untrusted environments.

What You Should Do

  • Use a VPN: Always connect to an always-on, full-tunnel VPN before conducting any sensitive work or accessing corporate resources on public Wi-Fi. Ensure your VPN is active before any other network activity.
  • Disable WPAD: Organizations should disable the Web Proxy Auto-Discovery Protocol (WPAD) where it is not strictly necessary and restrict proxy configuration retrieval to only approved internal hosts.
  • Implement Encrypted DNS: Utilize encrypted DNS in strict mode to help prevent malicious DNS responses from redirecting traffic.
  • Restrict Device-Code Authentication: Identity teams should block device-code authentication methods where they are not explicitly required.
  • Verify URLs and Certificates: Employees should meticulously verify website addresses and be vigilant for any certificate warnings before entering credentials on any hotel or public network.
  • Enhance User Awareness: Companies must reinforce security guidance through awareness programs covering cloud platform abuse attacks and ensure users know how to promptly report suspicious captive portals.
  • Prioritize Mobile Data: For travelers, the safest option for sensitive logins is to use mobile data whenever possible, avoiding public Wi-Fi entirely for critical tasks.
  • Exercise Caution with Downloads: Avoid unexpected software updates or downloads prompted on public Wi-Fi networks. Immediately stop any activity if your browser displays a certificate or privacy warning.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

North Korean Hackers Use Empty Crypto Transfers to Hide Malware Servers

Next Post

Apache NiFi Critical Vulnerabilities Enable Authorization Bypass

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Apache NiFi Critical Vulnerabilities Enable Authorization Bypass
August 4, 2026
Midnight Blizzard Hacks Hotel Wi-Fi to Steal Cloud Credentials From Travelers
August 4, 2026
North Korean Hackers Use Empty Crypto Transfers to Hide Malware Servers
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us