Image Credits: Russian hackers exploit hotel Wi-Fi networks to spy on travelers, Microsoft warns. AI-generated illustration created by Open Chronicle using ChatGPT (OpenAI). August 2026. This image is illustrative and does not depict a real-world scene.
By Open Chronicle with agencies
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world in an espionage campaign designed to steal travelers’ login credentials and infect devices with sophisticated malware, according to a new report from Microsoft.
The operation has been attributed to Storm-2945, a subgroup of the Russian cyber-espionage organization Midnight Blizzard, which Western intelligence agencies associate with Russia’s Foreign Intelligence Service (SVR).
Microsoft said the campaign was first detected in early May and targets hotels and other hospitality venues that require guests to connect through captive portal Wi-Fi networks, where users must log in via a web page before gaining internet access.
Fake login pages and software updates
Researchers say the attackers manipulate internet traffic on compromised Wi-Fi networks, redirecting users to fraudulent Microsoft authentication pages or fake browser and operating system update screens.
The fake login pages are designed to capture Microsoft 365 usernames and passwords, while the counterfeit update prompts trick users into downloading malicious software using a social engineering technique known as ClickFix, which persuades victims to install the malware themselves.
Cybersecurity company ReliaQuest, which first disclosed the campaign in July, reported that hotels in several U.S. cities, as well as locations in India and Saudi Arabia, have been affected.
Conference centres and other venues offering public Wi-Fi have also been targeted, with corporate travelers appearing to be the primary focus of the operation.
Two powerful malware families
Microsoft identified two primary malware families used during the attacks.
The first, CornFlake, is a remote access trojan that provides attackers with long-term control over infected Windows computers. Once installed, it can steal files, record keystrokes, capture passwords and authentication tokens, access microphones and cameras, detect removable storage devices and allow remote control of compromised systems.
The second malware, ChocoShell, is designed to rapidly harvest browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials. Unlike CornFlake, which is intended to maintain persistent access, ChocoShell focuses on quickly extracting sensitive information that can be used to access cloud services and corporate accounts.
Microsoft also warned that the campaign may be expanding beyond Windows devices. Some of the fake update pages contain instructions encouraging Android users to download malicious applications.
Attribution differs from earlier assessment
Microsoft’s conclusions differ from an earlier assessment by ReliaQuest, which suggested the campaign resembled tactics associated with APT28, also known as Fancy Bear or Forest Blizzard, a hacking group linked to Russian military intelligence.
Instead, Microsoft attributes the activity to Storm-2945, which it describes as part of the broader Midnight Blizzard organization, also known as APT29, Cozy Bear and BlueBravo.
The group has previously been linked to cyber-espionage campaigns targeting governments, diplomatic missions, defence contractors, energy companies, media organisations and political institutions in support of Russian foreign policy objectives.
Travelers urged to remain vigilant
Cybersecurity experts warn that the threat extends beyond hotels. Any organisation operating captive portal Wi-Fi networks, including airports, conference centres, universities, healthcare facilities, co-working spaces and large event venues, could become a target.
Researchers recommend that travelers verify software updates only through official channels, avoid entering credentials into unexpected login pages, enable multi-factor authentication and use virtual private networks (VPNs) when connecting to public Wi-Fi.
As cyber-espionage campaigns become increasingly sophisticated, security experts say public wireless networks remain one of the most attractive attack vectors for state-sponsored hacking groups seeking access to sensitive corporate and government information.