logo

Travelers targeted when logging into hotel Wi-Fi networks

ID: 1a3c580e-422b-5cc0-863e-b4e89f1d5901

STIX ID: report--1a3c580e-422b-5cc0-863e-b4e89f1d5901

Feed Name: Malwarebytes Blog

Threat Score
80/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

...
...

**CaptiveCrunch campaign:** Microsoft warns a Russian-linked group is abusing hotel/conference captive‑portal Wi‑Fi to intercept DNS/HTTP traffic, redirect users to phishing pages, push fake update dialogs that install malware (notably CornFlake RAT and ChocoShell infostealer), and perform MitM attacks to harvest credentials and tokens; the report outlines observed fake dialogs and provides traveler-focused mitigations such as using cellular hotspots, VPNs with kill switches, certificate inspection, and avoiding downloads from captive portals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.