The Hospitality Newsletter
Today Friday, August 7, 2026
Original technology The Hospitality Newsletter Team · ·For: IT, GM, Owner

Russian Hackers Target Hotel Wi-Fi in CaptiveCrunch Cyber Attacks

Microsoft warns that the Russian-linked Storm-2945 group is compromising hotel Wi-Fi networks to steal login tokens and deploy the CornFlake trojan.

The short answer

Russian hackers are actively compromising hotel Wi-Fi networks to steal login tokens from business travelers. The CaptiveCrunch campaign bypasses multi-factor authentication and installs the CornFlake remote-access trojan on guest devices.

Russian Hackers Target Hotel Wi-Fi in CaptiveCrunch Cyber Attacks
Photo: Mikhail Nilov / Pexels

The short version

  • CaptiveCrunch targets business travelers via compromised hotel Wi-Fi to steal Microsoft 365 login tokens.
  • Storm-2945, linked to Russia's Midnight Blizzard, bypasses multi-factor authentication using fake sign-in prompts.
  • CornFlake trojan is deployed to track keystrokes, collect files, and monitor audio and video on guest devices.

Microsoft has identified a Russian-linked cyber espionage campaign, dubbed CaptiveCrunch, actively compromising hotel Wi-Fi networks since early May to target business travelers. Attackers deploy fake network verification pages that trick guests into bypassing multi-factor authentication, allowing hackers to steal Microsoft 365 login tokens and deploy the CornFlake remote-access trojan. [1]

How does the CaptiveCrunch campaign compromise hotel networks?

The attackers exploit hotel and hospitality Wi-Fi systems to display fraudulent verification pages, sign-in prompts, and fake software updates to guests attempting to connect to the internet. [1] According to Asian Hospitality, these prompts are designed to look identical to legitimate hotel Wi-Fi captive portals. [2] When victims interact with these pages, they are redirected to Microsoft’s device-code login process. [1] The hackers provide a specific code, and once the guest enters it, the attackers gain approval to access the victim's account. [1] This method grants the hackers valid login tokens, meaning they do not need to steal the user's password or directly bypass multi-factor authentication protocols. [2]

close up of a laptop screen displaying a fake wi-fi login page
Photo: Pixabay / Pexels

What is the connection to Russian intelligence groups?

Microsoft traced the CaptiveCrunch campaign to a threat actor tracked as Storm-2945. [1] In a blog post detailed by Asian Hospitality, Microsoft noted that Storm-2945 is directly connected to Midnight Blizzard, a well-known hacking group operating out of Russia. [2] The campaign has been highly active since early May, specifically singling out business travelers who rely on hospitality networks to conduct corporate work. [1]

How does the CornFlake trojan infect guest devices?

Beyond stealing login credentials, the CaptiveCrunch operation installs dangerous malware directly onto the devices of hotel guests. [1] Microsoft discovered that the campaign deploys a Windows remote-access trojan named CornFlake. [2] This malware creates a severe security risk that extends far beyond compromised Microsoft 365 tokens. [1] Once installed, CornFlake executes multiple surveillance functions on the victim's machine. [2] The trojan can steal local account information, track user keystrokes, and collect private files. [1] Furthermore, Asian Hospitality reports that CornFlake has the capability to take screenshots and actively monitor the device's audio and video feeds without the user's knowledge. [2]

Where are the compromised Wi-Fi gateways located?

A separate cybersecurity report published in July by ReliaQuest confirmed that attackers are actively targeting Microsoft 365 users through these compromised hospitality networks. [1] ReliaQuest found that the hackers successfully redirect guests to fake sign-in pages entirely through the Wi-Fi gateway, without needing to send phishing emails or gain prior access to the victim's laptop or phone. [2] The firm identified compromised Wi-Fi gateways in several cities across the United States. [1] The attacks are also international in scope, with compromised hospitality networks discovered in countries including India and Saudi Arabia. [2] These breaches predominantly occur at hotels and other hospitality organizations. [1]

server rack in a dark room with glowing lights
Photo: panumas nikhomkhai / Pexels

What role do artificial intelligence tools play in the attacks?

The attackers utilize artificial intelligence to facilitate the CaptiveCrunch campaign. [1] During the investigation into the breaches, Microsoft collaborated with AI companies Anthropic and OpenAI. [2] The joint investigation confirmed that the hackers employed AI tools to support their operations against hotel networks. [1] Following these discoveries, Microsoft advised all travelers to use mobile data connections whenever possible and to avoid utilizing hotel Wi-Fi networks for important or sensitive activities. [2]

Have hospitality organizations faced similar threats recently?

This is not the first time hackers have focused on the hospitality industry to steal credentials. [1] Asian Hospitality noted that last year, Microsoft warned the industry about a separate phishing campaign. [2] In that instance, attackers targeted hospitality organizations by sending fake Booking.com emails designed to deliver malware and steal user credentials. [1]

Threat Component Details Identified by Microsoft
Campaign Name CaptiveCrunch
Threat Actor Storm-2945 (tied to Russia's Midnight Blizzard)
Malware Deployed CornFlake (Windows remote-access trojan)
Malware Capabilities Steal account info, track keystrokes, collect files, take screenshots, monitor audio/video
Target Demographic Business travelers
Affected Locations U.S. cities, India, Saudi Arabia

Reported by

This article was written from the following reporting. Follow the links for the original coverage.

Frequently asked

+What is the CaptiveCrunch campaign?

CaptiveCrunch is a global hacking campaign active since early May that targets business travelers through compromised hotel Wi-Fi networks to steal login details.

+Who is behind the hotel Wi-Fi attacks?

Microsoft linked the attacks to Storm-2945, a group connected to Russia’s Midnight Blizzard.

+How do hackers steal login details on hotel Wi-Fi?

Attackers display fake verification pages and sign-in prompts on the Wi-Fi network, redirecting victims to Microsoft’s device-code login process. Guests are tricked into entering an attacker-provided code, granting access via valid login tokens without needing passwords.

+What is the CornFlake trojan?

CornFlake is a Windows remote-access trojan installed by the attackers. It can steal account information, track keystrokes, collect files, take screenshots, and monitor device audio and video.

+Where have compromised Wi-Fi gateways been found?

A July report from ReliaQuest found compromised Wi-Fi gateways mainly at hotels in several U.S. cities, as well as in India and Saudi Arabia.

+Did the hackers use AI in these attacks?

Yes, an investigation by Microsoft, Anthropic, and OpenAI found that the attackers used AI tools to support the CaptiveCrunch campaign.

Keep reading