Russian hackers found in hotel chain WiFis, targeting travelers
The supply chain attack starts with a vendor – a company that provides and manages WiFi networks for hotels, airports, and other clients.

Image by Cybernews.
- Russian state-linked hackers have compromised public WiFi networks at hotels, airports, conference centers, and casinos.
- Researchers linked the campaign to providers serving seven of the top 10 US hotel chains.
- Attackers redirect travelers to fake login pages and prompts that steal credentials or install malware.
- Microsoft urges travelers to avoid public WiFi prompts and use mobile hotspots, cellular data, or VPNs.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Russian state-linked hackers have infiltrated WiFi networks at major hotels, airports, and conference centers. They operate through “multiple” firms that manage networks for the hospitality sector, Microsoft warns. The attackers redirect travelers to fake websites and authentication portals, steal data, and infect victims with malware.
Russian hackers, known as Cozy Bear, APT29, or Midnight Blizzard, have been lurking in WiFi hotspots at hotels, airports, conference centers, and casinos in the US and abroad.
Three North American companies managing WiFi networks for 7 of the top 10 hotel chains in the US were likely compromised this summer, according to a report by Black Lotus Labs.
It appears that the attackers retain access to this day.
Microsoft has issued a fresh warning saying that a new campaign is targeting travelers.
The renewed activity suggests that “multiple hospitality managed service providers are implicated,” Microsoft Threat Intelligence said in updated research.
“Continued access to these upstream providers has likely enabled this rapid re-deployment.”
The operation is AI-augmented. On compromised WiFi networks, attackers manipulate network traffic and redirect their targets to spoofed captive portals or other authentication portals. Successful attacks infected victims with infostealer and remote access malware.
The hackers also renewed their infrastructure with new domains and IP addresses, which are used for redirecting and hosting malicious websites and payloads.
“Once they control the WiFi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026,” a previous ReliaQuest report reads.
Cybersecurity researchers call this malicious campaign “Captive Crunch.” Microsoft attributes the new campaign to a sub-cluster of the Russia-linked threat actor Midnight Blizzard.
The attacks come in waves
The cyberattacks have escalated since February, when Microsoft first detected DNS tampering. The attackers used compromised WiFi hotspots to intercept traffic, display fake captive portals, and manipulate DNS and HTTP requests to redirect victims to malicious servers they control.
In June, a new malicious campaign stemmed from the first company that manages hotel networks, dubbed MSP 1 (Managed Service Provider 1).
On July 23rd, another attack wave began, linked to MSP 2, another managed service provider. The next day, it was quickly followed by another MSP 3-linked campaign.
We specifically observed activity stemming from a dozen IP addresses that geo-locate to the Las Vegas area in the weeks prior to the Black Hat/DEF CON cybersecurity conference,Black Lotus Labs noted in its report.
At least 70 victim IP addresses, each belonging to a compromised network, were identified by researchers and associated with the campaign over the summer.
The attacks continue despite previous disclosures and public reporting.
Multiple malware variants have been delivered, including fully-featured Windows remote access trojans capable of video and audio spying, stealing credentials, and monitoring all media.
Attackers used a variety of ClickFix techniques, like fake Windows updates, browser updates, driver repairs, security checks, or a simple CAPTCHA, which provided instructions and tricked users into downloading and executing the malware themselves.
Don’t trust public WiFi
Microsoft says that all travelers should treat hotel, airport, conference center, and other public WiFi networks as untrustworthy. Prioritize private connectivity options such as mobile hotspots, satellite connectivity, and eSIM-based cellular data connections.
“Avoid downloading software updates, certificates, browser updates, network troubleshooting tools, or security utilities presented through captive portals or other unexpected web prompts,” the report warns.
An encrypted tunnel (VPN) with private DNS settings is another security measure that prevents similar attacks.
“Consider using enterprise-managed travel routers or hotspot devices that establish encrypted tunnels back to trusted corporate infrastructure before accessing sensitive resources,” Microsoft added.