Russia-Linked Hackers Went Right Back Into Hotel Wi-Fi Login Pages Two Months After Microsoft Exposed Them
Microsoft called out Midnight Blizzard for hijacking hotel Wi-Fi login pages in July. By late September the spies were back, because they never left the vendors running the networks.

Getting publicly exposed by Microsoft didn't slow Russia's hotel Wi-Fi spies down much. On September 29, Microsoft saw Storm-2945, a sub-cluster of the Russia-linked group Midnight Blizzard, restart its campaign against the captive portals travelers click through to get online at hotels. The company updated its CaptiveCrunch report on October 5, two months after first exposing the operation on July 31.
Midnight Blizzard, also known as APT29 or Cozy Bear, is the crew behind the SolarWinds supply chain attack and the 2024 breach of Microsoft's own corporate email. They don't scare easily.
They never left the plumbing
The quick comeback has a simple explanation. "Storm-2945's continued access to these upstream providers has likely enabled this rapid re-deployment," Microsoft wrote, pointing to Lumen's Black Lotus Labs, which says multiple hospitality managed service providers are implicated.
Black Lotus Labs' findings are grim. Three North American companies that manage Wi-Fi for 7 of the top 10 US hotel chains were likely compromised this summer, and the attackers appear to still have access. At least 70 victim IP addresses, each one a compromised network, were tied to the campaign over the summer. Researchers also tracked activity from a dozen IP addresses in the Las Vegas area in the weeks before the Black Hat and DEF CON security conferences.
How the attackers first got into those networks is still under investigation. But affected sites share common equipment and management systems, which suggests access to shared services rather than one hotel at a time.
How the trap works
Since early May, the group has been manipulating DNS and HTTP traffic on captive-portal networks worldwide. Travelers get redirected to phishing pages mimicking Microsoft services that abuse the device code sign-in flow in Microsoft Entra ID, the same family of MFA-dodging tricks as kits that relay one-time codes in real time.
Others get malware. When a browser runs its automatic connectivity check, the hijacked network answers with a fake browser or OS update. ClickFix tricks (bogus Windows updates, driver repairs, security checks, CAPTCHAs) talk victims into running the payload themselves. Those include fully featured Golang remote access trojans that grab files and keystrokes, steal credentials and session tokens, and record audio and video.
The new wave brought a Rust variant of the CornFlake infostealer "with characteristics consistent with continued AI-enabled malware development." Microsoft says the group used AI for a significant portion of its operations, and thanked Anthropic and OpenAI for their collaboration and Google Threat Intelligence Group for helping track the reemergence. There are signs of Android targeting too, with ClickFix pages serving APK install instructions.
Who they want
ReliaQuest has seen the activity at hotels, conference centers and other shared venues, and assesses the real target is corporate travelers' accounts. That fits a pattern of state hackers going after people with valuable inboxes, like the Chinese operators phishing AI policy experts.
Microsoft's advice is blunt: treat hotel, airport and conference Wi-Fi as untrustworthy. Use a mobile hotspot or eSIM data instead, never download updates, certificates or security tools offered through a captive portal, and run a VPN with private DNS.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free