Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch (itnews.com.au)
- Reference: 0184840946
- News link: https://yro.slashdot.org/story/26/08/04/0523203/russia-linked-midnight-blizzard-group-hijacks-hotel-wi-fi-with-captivecrunch
- Source link: https://www.itnews.com.au/news/russia-linked-midnight-blizzard-group-hijacks-hotel-wi-fi-with-captivecrunch-627911
> Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's [2]technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals.
>
> A [3]related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector.
>
> [...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.
[1] https://www.itnews.com.au/news/russia-linked-midnight-blizzard-group-hijacks-hotel-wi-fi-with-captivecrunch-627911
[2] https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
[3] https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
DEFCON (Score:2)
I'm not too worried, as hotels should have these patched within two weeks. Just thank God there's no hacker conference this weekend in a city like Las Vegas, which has the most hotel rooms in America.
But remember... (Score:2)
We're NOT at war with Russia!
Re: (Score:2)
Countries spy on each other even during times of peace.
Did you have a point?
Re: (Score:2)
When we are at war with Russia, neither side is going to be uncertain of that fact. This isn't war, it's just a little light foreplay between nuclear armed super powers.
Does Microsoft not sign packages ? (Score:2)
If so how are bad packages installed ? Debian [1]keeps keys in /etc/apt/trusted.gpg.d/ [debian.org] and has done so since 2005.
[1] https://wiki.debian.org/SecureApt#Basic_concepts
Re: (Score:1)
No I'll just decline when the hotel wifi asks for my SSN and date of birth
Re: Don't ever use hotel WiFi (Score:2)
I bring a 4 meter cable since sometimes WiFi performance poor especially affecting connections via VPNs. Usually there is a network cable into TV , if no router port. Need a cable extension adapter. Does not fully avoid a compromised connection if hotel system but beats weak wifi. There are other precautions such as no admin privileges on user accounts etc
Re: (Score:3)
Just use 078-05-1120. It's the number on the SS card that came with my new wallet.
Note that is not illegal to provide an incorrect SSN to parties other than the government or those with a duty to report financial transactions.
If they ask for a birthdate, reply like Crocodile Dundee: "In the summer."
Re: (Score:1)
The surveillance state has conscripted hotels to verify identity. They'll tell you its for fraud prevention, or because local laws require it. But the vast majority of hotels in the US (and probably Canada) require a photo id. So at the very least they've recorded your driver's license number and full name and DOB. It's automatic if they have a DL scanner (either barcode or image-based software)