• Hype
  • Murai
  • Lipstiq
  • Varnam
  • Hangat
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Mobile Gaming
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Artificial Intelligence
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
    • Contact Us
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Mobile Gaming
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Artificial Intelligence
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
    • Contact Us
No Result
View All Result
Lowyat.NET
No Result
View All Result

Microsoft: Russian Hackers Are Stealing User Data Via Hotel Wi-Fi

The threat actors were part of an operation called "CaptiveCrunch".

by John Law
August 5, 2026
Image: Techspot.

Image: Techspot.

405
SHARES
Share on WhatsappShare on TelegramThreads

Microsoft recently put out a warning to travellers, saying their personal data and information may have been compromised by Russian hackers. Specifically, the Russian threat actors backed by the state have been targeting Wi-Fi networks at hotels and conferences all over the world.

CaptiveCrunch And No, It’s Not A Cereal

Microsoft named the operation CaptiveCrunch, presumably after the popular US cereal mascot, and that Russian hackers from the group Storm-2945 — which itself is a branch of Midnight Blizzard — have been targeting the networks of establishments within the hospitality industry. For the uninitiated, Midnight Blizzard is a group of black hat hackers, believed to have links to Russia’s Foreign Intelligence Service (SVR).

Microsoft Russian Hackers hotels global 2
Image: Microsoft.

“Since February 2026, Storm-2945 has conducted AI-augmented operations including targeted device code and OAuth code phishing campaigns leading to Entra device registration and subsequent data collection from Microsoft 365. Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem.”

The attacks aren’t just limited to Windows devices either. Microsoft states in its blog that the hackers may also be targeting Android users, using similar techniques like the ClickFix landings, including “instructions” for Android devices to download and install the offending APK file.

Related Article Microsoft Tests Cloud Rebuild To Restore Windows 11 Without Drives

Tools Of The Trade

Microsoft Russian Hackers hotels global 1
Image: Microsoft.

One of the tools used by the Russian hackers is a program called CornFlake. As per Microsoft’s explanation: “CornFlake is a full-featured Windows RAT written in Go that serves as Storm-2945’s primary persistent implant. Microsoft has observed the threat actor rapidly iterating on this malware layer, which features customizable capabilities from the social engineering user interface and data collection capabilities to anti-detection and evasion techniques. On initial execution, CornFlake operates in dropper mode: it displays a convincing fake progress window designed to occupy the victim’s attention while the binary copies itself to %APPDATA%\svchost32\svchost32.exe and establishes persistence.”

To cut a long story short, CornFlake can be used to create fake options that look legit, including winupdate, defender, directx, vcredist, sysopt, and netfix, to name a few. If that wasn’t bad enough, Microsoft also says that the hackers have leveraged AI in helping with their endeavours.

If you’re travelling, it is considered best practice to never conduct any form of updates on Windows through an unsecured connection, most especially through a hotel network.

(Source: Microsoft, Techspot, ReliaQuest)

Filed Under Hackersmicrosoft
Updated 7:47 pm, Wed, 5 August 26
SendShareShareShare162Tweet101

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    News

    JPJ To Suspend MyEG, Zetrix AI Services From 5 October 2026

  2. 2
    Mouse / Mouse Pad

    Lenovo Unveils A Transparent Mouse With 90-Day Battery Life (Updated)

  3. 3
    Artificial Intelligence

    Google To Restrict Gemini Model Access For Free, AI Plus Users From 9 October

  4. 4
    Console

    PS5 Slim Gets Silent Hardware Update; Another Cooling System Change

  5. 5
    CelcomDigi

    CelcomDigi Announces Three Programs As Part Of Next Phase Of CD:NXT

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Varnam
  • Hangat
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Editorial Policy
  • Terms of Use
  • Contact Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
  • Forums
  • Laptops
  • Telco
  • Mobile
  • Gaming
  • Artificial Intelligence
  • Fintech
  • Cryptocurrency
  • Cyber Security
  • Hybrid Vehicles
  • Advertise with Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
  • Forums
  • Laptops
  • Telco
  • Mobile
  • Gaming
  • Artificial Intelligence
  • Fintech
  • Cryptocurrency
  • Cyber Security
  • Hybrid Vehicles
  • Advertise with Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.