• Travelers beware Microsoft experts warn hotel Wi-Fi can be hijac

    From TechnologyDaily@1337:1/100 to All on Tue Aug 4 14:15:26 2026
    Travelers beware Microsoft experts warn hotel Wi-Fi can be hijacked to
    infect your devices with dangerous malware

    Date:
    Tue, 04 Aug 2026 13:00:00 +0000

    Description:
    Russian criminals are targeting hotel Wi-Fi networks with captive portals and using them to deploy infostealers.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference
    centers Victims redirected to fake Microsoft 365 logins or bogus update
    pages, spreading CornFlake and CocoShell malware CornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokens Threat actors are taking over Wi-Fi networks in hotels and conference centers and using the log-in portals to steal credentials and deploy information-stealing malware , experts have claimed.

    Researchers from Microsoft have published a new report outlining how they spotted Russian state-sponsored actors, known as Midnight Blizzard or APT29, attacking captive portal equipment - networking hardware and software that manages the login page users see before accessing public Wi-Fi. When connecting to a hotel network, users are often redirected to a page where
    they must enter their room number, accept the terms of service, and click Connect - that redirection is handled by the captive portal. Latest Videos From TechRadar Watch full video here: CornFlake and CocoShell Microsoft did not explain exactly how this gear is attacked. However, when users try to log in on compromised networks, they may be redirected to a fake Microsoft 365 login portal that steals their credentials.

    They may also be redirected to device code phishing pages abusing Microsoft Entra ID authentication flows. Finally, the researchers also saw the captive portals being used to display fake browser and OS update pages that trick victims into downloading infostealers. You may like Hackers are establishing persistence in hospitality and hotels by posing as guests with poisoned ZIP archives, but no one knows what their plan is Hackers are hijacking
    legitimate news websites and reviews to drum up publicity Experts warn Claude feature hijacked by hackers to launch major malware campaign

    So far, MIcrosoft found two malware variants being distributed: CornFlake,
    and CocoShell.

    CornFlake acts as an infostealer capable of grabbing keystrokes and
    clipboard, running remote shell access, grabbing screenshots, using the microphone and the webcam, stealing browser credentials and cookies, exfiltrating files, and more. It presents itself as a Cloud Sync Service
    while using multiple persistence mechanisms. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
    with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    CocoShell, on the other hand, is an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD
    tokens, and Wi-Fi credentials.

    APT29 is one of the most documented state-sponsored threat actors out there. Its been active for years and is well-known for its links to Russias Foreign Intelligence Service and notable attacks on high-ranking western targets,
    such as US and German Government officials, as well as SolarWinds and Microsoft. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/travelers-beware-microsoft-experts-warn -hotel-wi-fi-can-be-hijacked-to-infect-your-devices-with-dangerous-malware


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)