Internet access has become essential for most people. Therefore, travellers often use free Wi-Fi whenever they stay at hotels. However, cybercriminals have also become increasingly advanced with changing technology. They now use new techniques to target unsuspecting users. Against this backdrop, Microsoft has issued an important warning for hotel visitors.
According to media reports, Microsoft published a report on July 31 about a campaign called CaptiveCrunch. The company said attackers target Wi-Fi sign-in systems inside hotels and conference centres. After gaining control, criminals can show fake software updates to people connecting with those networks. Additionally, users may encounter fraudulent login pages designed to appear genuine.
When someone joins a new hotel network, a sign-in page usually appears first. That screen commonly asks visitors to accept terms and conditions. This system carries the name Captive Portal. Microsoft says attackers have specifically targeted this mechanism during CaptiveCrunch operations.
In some cases, criminals can also manipulate DNS and HTTP traffic across compromised networks. Consequently, someone attempting to open one website may reach a completely different destination. Attackers can therefore redirect users towards pages under their control.
Fake Microsoft Login Pages Can Steal Sessions and Credentials
Attackers also use another method involving login credentials and active sessions. A Microsoft sign-in page can appear almost identical to the genuine version. Therefore, victims may enter sensitive information without noticing anything unusual.
Microsoft has observed such pages since July 16. Some direct users towards Device Code Authentication. This function represents a legitimate Microsoft login feature. However, attackers misuse that system during fraudulent operations.
The most dangerous element involves the website receiving the code. Users actually enter information on a genuine Microsoft page. However, the attacker originally initiated that code. Consequently, this method appears more advanced than many conventional phishing techniques.
Microsoft also says Storm-2945 has used artificial intelligence during cyber operations since February. Those activities include Device Code techniques alongside OAuth-based phishing methods. According to the company, AI supported an important portion of the group’s work.
However, Microsoft did not identify which artificial intelligence systems the attackers used. The company also withheld details about tasks that criminals automated through AI.
Malware Can Record Keystrokes, Steal Passwords and Monitor Devices
If users run attacker-supplied software or commands, sensitive information can leak from their devices. Microsoft says criminals can perform several activities after infecting a system.
Attackers may record information typed through the keyboard. They can also capture screenshots from infected devices. Furthermore, criminals may record audio alongside video. They can steal browser cookies and retrieve stored passwords.
Malware can also monitor activity involving connected USB drives. Additionally, attackers may run remote commands through PowerShell or Command Prompt. They can route internet traffic through a proxy under their control.
Therefore, criminals may gain access beyond one infected device. Connected accounts and other important information can also become exposed.
Android users also face potential risks from this campaign. Some ClickFix pages instruct them to download APK files from external sources. Afterwards, users receive directions to install those packages manually.
However, Microsoft says Android-focused tools currently show less activity than the Windows-related component. Even so, the company’s warning makes clear that the threat can affect both platforms.














