The campaign, called ‘CaptiveCrunch’, has been active since at least May, according to Microsoft. It targets Wi-Fi networks at hotels, conference centres and other places that use public guest networks.
“To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries,” the company said in its report.
Microsoft added that the attacks have been linked to Storm-2945, a hacking group that is reportedly connected to the Russian cybercrime group Midnight Blizzard, also known as APT29 or Cozy Bear.
How does the hotel Wi-Fi attack work?
The attack begins when a traveller tries to connect to a hotel’s Wi-Fi. Usually, guests are taken to a login page, also known as a captive portal, where they enter details before getting internet access. Hackers can compromise these systems and change what users see on their screens.
Instead of a normal Wi-Fi login page, travellers may see fake messages asking them to update their browser, install a security tool or fix a network problem. These messages can look like genuine Windows or Google alerts. For example, “Our systems have detected unusual traffic from your computer network. Please complete the security check to access Google Search.”
If a person downloads the file or follows the instructions, malware can be installed on their device.
Microsoft said several types of fake pop-ups may appear when someone connects to a compromised Wi-Fi network.
These can look like:
A Windows update screen
A fake Windows Security virus scan
A DirectX installer
A Microsoft Visual C++ installer
A fake disk optimisation tool
A Windows network troubleshooting tool
A browser update message
A document viewer installer
Hackers can record audio and video
Once the malware gets into a device, hackers can gain significant control over it.
Microsoft said the attackers can record audio and video, capture screenshots, track keystrokes and steal browser cookies and saved passwords. The attackers can also use stolen passwords to access accounts. Microsoft said some victims could be redirected to fake login pages designed to steal their Microsoft 365 credentials.
If a person enters their password on such a page, hackers could gain access to their emails, OneDrive files and, in some cases, corporate networks.
How to prevent
Microsoft has advised travellers to be extra careful when using hotel and public Wi-Fi.
The company recommends using a personal mobile hotspot instead of public Wi-Fi whenever possible. Travellers should also avoid downloading software, browser updates or security tools offered through hotel Wi-Fi login pages or unexpected pop-ups.
Users should also be careful about entering passwords on pages that suddenly appear after connecting to a public network.

