Travelers targeted when logging into hotel Wi-Fi networks
ID: 1a3c580e-422b-5cc0-863e-b4e89f1d5901
STIX ID: report--1a3c580e-422b-5cc0-863e-b4e89f1d5901
Feed Name: Malwarebytes Blog
**CaptiveCrunch campaign:** Microsoft warns a Russian-linked group is abusing hotel/conference captive‑portal Wi‑Fi to intercept DNS/HTTP traffic, redirect users to phishing pages, push fake update dialogs that install malware (notably CornFlake RAT and ChocoShell infostealer), and perform MitM attacks to harvest credentials and tokens; the report outlines observed fake dialogs and provides traveler-focused mitigations such as using cellular hotspots, VPNs with kill switches, certificate inspection, and avoiding downloads from captive portals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
