Russian State-Sponsored Hackers Target Global Hotel Wi-Fi Networks for Espionage
A sophisticated campaign by Russian state-sponsored hackers is compromising hotel Wi-Fi networks worldwide, aiming to steal traveler credentials and deploy advanced espionage malware. The attacks leverage fake login pages and malicious software updates, primarily targeting corporate travelers and their sensitive data.
# Russian State-Sponsored Hackers Target Global Hotel Wi-Fi Networks for Espionage
Russian state-sponsored hackers have been actively compromising hotel Wi-Fi networks globally to steal login credentials and infect devices with espionage malware, according to recent findings by cybersecurity researchers.
## Midnight Blizzard's New Sub-Cluster: Storm-2945
In a report published by **Microsoft** on Friday, the activity is linked to **Storm-2945**, a sub-cluster of the Russian espionage group **Midnight Blizzard** (also known as **APT29**, **Cozy Bear**, and **BlueBravo**). This group is widely believed by Western intelligence agencies to be connected to Russia's Foreign Intelligence Service (**SVR**).
First observed by **Microsoft** in early May, the campaign primarily targets hotels and other hospitality venues that utilize captive portals for Wi-Fi access.
## Deceptive Tactics: Fake Login Pages and Malicious Updates
Attackers manipulate internet traffic on compromised networks, redirecting victims to fraudulent **Microsoft** login pages or fake browser and operating system update screens. These deceptive pages are designed to either harvest credentials or deliver malware.
Cybersecurity firm **ReliaQuest**, which initially disclosed this activity in July, confirmed that the operation has impacted hotels and hospitality organizations across several U.S. cities, as well as in India and Saudi Arabia. Conference centers and other shared venues have also been affected, with corporate travelers appearing to be the primary targets.
## Two Primary Attack Vectors
**Microsoft** identified two main techniques employed by the hackers:
1. **Credential Theft**: Victims are redirected to fake **Microsoft** authentication pages, allowing the attackers to intercept login credentials and gain unauthorized access to **Microsoft 365** accounts.
2. **Malware Delivery**: Users are presented with fabricated browser or operating system update pages, tricking them into downloading malware through social engineering techniques dubbed 'ClickFix'.
## Espionage Malware: CornFlake and ChocoShell
The campaign utilizes two distinct malware families:
* **CornFlake**: This is a remote access trojan (**RAT**) designed for persistent control over infected **Windows** computers. It can collect files, record keystrokes, steal passwords and authentication tokens, capture audio and video, detect removable media, and enable remote system control.
* **ChocoShell**: An information stealer focused on quickly harvesting browser cookies, saved passwords, **Microsoft 365** single sign-on tokens, and Wi-Fi credentials. While **CornFlake** establishes a long-term foothold, **ChocoShell** is geared towards rapid credential extraction for accessing cloud accounts and online services.
**Microsoft** also noted that the operation might be expanding beyond **Windows** systems, with some fake update pages including instructions for **Android** users to download malicious applications.
## Attribution Differences and Broader Implications
While **ReliaQuest** initially suggested the tactics resembled those of **APT28** (also known as **Fancy Bear** or **Forest Blizzard**), another Russian military intelligence hacking group, **Microsoft** firmly attributes the activity to **Storm-2945** within **Midnight Blizzard**. **APT28** has previously been linked to router-based campaigns targeting **Microsoft 365** accounts and exploiting vulnerable internet routers for espionage.
Though the current activity has largely focused on hotels, **ReliaQuest** has warned that any organization operating captive portal networks β including airports, conference centers, co-working spaces, universities, healthcare facilities, and event venues β could become a target. This highlights a significant risk for professionals and organizations relying on public or semi-public Wi-Fi infrastructure.