ADVERTISEMENT

Russian spies hijack hotel WiFi worldwide to infect travelers with malware, Microsoft warns

Russia's Midnight Blizzard is using fake Windows and browser updates to infect business travelers with malware and steal Microsoft 365 credentials.

guest wifi

Image by ymgerman | Shutterstock

Stefanie Schappert
Stefanie Schappert Senior Journalist
August 3, 2026 3 min read
Key takeaways:
Microsoft reveals hotel WiFi espionage campaign

Hotel WiFi becomes a Russian spy trap

Russia Midnight Blizzard Hotel WiFi attacks - diagram
Microsoft's Midnight Blizzard attack chain shows how compromised hotel WiFi can lead to credential theft, malware infections, and long-term access to corporate cloud accounts. Image by Microsoft Threat Intelligence
WiFi hackers
Russian spies target hotel WiFi networks worldwide to deploy the CornFlake trojan and ChocoShell infostealer. Image by Cybernews.
“Executives, government officials, and employees routinely access sensitive corporate resources from hotels, often assuming the network is legitimate,”
Centrella says.
ADVERTISEMENT

Fake updates unleash powerful malware

“Campaigns like this show that attackers are investing in persistent access through third-party infrastructure, allowing them to collect intelligence long before an organization detects unusual activity within its own environment,”
Centrella says.
Russia Midnight Blizzard Hotel WiFi attacks - Windows update
Attackers disguise malware as fake Windows update prompts to trick travelers into infecting their own devices. Image by Microsoft Threat Intelligence
Russia Midnight Blizzard Hotel WiFi attacks - clickfix
Microsoft says the campaign uses ClickFix social engineering to convince victims to run malicious commands. Image by Microsoft Threat Intelligence

How corporate travelers can stay secure

Stefanie Schappert
Senior Journalist
ADVERTISEMENT