Microsoft warns of large-scale Russian hacking campaign targeting hotel Wi-Fi networks worldwide
Microsoft says it has uncovered a large-scale hacking campaign by Russian actors targeting public Wi-Fi networks in hotels and conference centers around the world.
Microsoft has announced the discovery of a large-scale hacking campaign orchestrated by Russian threat actors, aimed at public Wi-Fi infrastructure in hotels, conference centers, and other venues globally. The attacks specifically target establishments that rely on captive portals — the authentication pages displayed when a device joins a public wireless network. According to Microsoft, the attackers may have compromised shared services utilized by multiple operators of such networks, potentially expanding the scope of the campaign.
As part of the operation, hackers covertly redirected users to phishing infrastructure under their control and delivered malicious software disguised as updates for browsers or operating systems. These fake update notifications were triggered in response to the automatic connectivity checks that browsers perform immediately after joining a new network. This approach allows attackers to intercept traffic or deploy malware before users can take protective measures.
Microsoft attributes the campaign to a group known as Storm-2945, which it links to Midnight Blizzard, an actor the company has repeatedly investigated. Microsoft states that members of Midnight Blizzard are associated with Russia's Foreign Intelligence Service. The same group is believed to be behind the 2020 cyberattack on U.S. government agencies via SolarWinds software, as well as the 2023 breach of the Outlook email client.

