Microsoft warns hotel/airport Wi-Fi is being hijacked to steal your login

According to the report, the attackers redirect users—for example, those who are logging into their Microsoft accounts via a hotel Wi-Fi network—to imitation phishing sites. There, the attackers capture device and OAuth codes, which they can use to take over said Microsoft accounts.
In addition, the attackers are believed to be installing malware on victims’ devices, including Trojans that record keystrokes, eavesdrop on device activity, spy via hijacked cameras, and forward sensitive files and passwords. Furthermore, the malware sets up remote access for the attackers to the infected devices.
It’s apparently made possible by compromised public Wi-Fi networks, like the ones you’d rely on in hotels and airports. The key question, of course, is how the attackers gain access to those networks, which Microsoft is currently investigating. It’s possible that the captive portals, where users agree to terms of use, play a role.
Microsoft states the following on this matter:
Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem.
Microsoft believes the hacker group Storm-2945 is responsible for this wave of CaptiveCrunch attacks. This group is associated with Midnight Blizzard, which in turn is believed to be part of the Russian Foreign Intelligence Service.
What you can do to stay safe
Public Wi-Fi networks are risky. Not only is there a non-zero chance for your data to be intercepted, but Wi-Fi hotspots can be exploited to track your physical location and even identify your physical body.





