Microsoft says Russian state-backed hackers have been compromising hotel and hospitality Wi-Fi networks to steal traveler credentials and plant espionage malware, according to reporting from The Record. The campaign is attributed by Microsoft to Storm-2945, a sub-cluster of Midnight Blizzard, the Russia-linked espionage group also known as APT29, Cozy Bear, and BlueBravo.
🤚 The Open-Palm Lobby Ambush
The attack vector is exquisitely ordinary: the captive portal, that little hotel Wi-Fi page where guests accept terms they will never read so they can send a spreadsheet from a carpeted room with one functioning lamp. Microsoft said the activity was first observed in early May and targets hotels and other hospitality venues where guests must log in through these portals before getting internet access.
Once attackers compromise the network path, victims can be redirected to fake Microsoft login pages or fraudulent browser and operating-system update screens. One route steals credentials for Microsoft 365 accounts. The other persuades users to install malware through so-called ClickFix social engineering, the increasingly popular ritual in which a human is convinced to execute the attacker’s instructions while believing they are fixing technology’s latest emotional breakdown.
The Record notes that ReliaQuest, which disclosed related activity in July, said hotels and hospitality organizations in multiple U.S. cities were affected, along with venues in India and Saudi Arabia. Conference centers and other shared venues may also be targets, with corporate travelers appearing to be a central focus.
👐 The Two-Handed Credential Buffet
Microsoft identified two main malware families in the campaign. CornFlake is described as a remote access trojan designed to give operators persistent control over infected Windows machines. According to The Record’s summary of Microsoft’s findings, it can collect files, record keystrokes, steal passwords and authentication tokens, capture audio and video, detect removable media such as USB drives, and allow remote control of compromised systems.
The second tool, ChocoShell, is an information stealer built for faster extraction: browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and Wi-Fi credentials. The naming convention suggests breakfast cereal and dessert. The functionality suggests a diplomatic security briefing where everyone slowly closes their laptop.
The campaign may not be limited to Windows. Some fake update pages reportedly include instructions for Android users to download and install a malicious app, because no luxury espionage experience is complete until your phone also receives turndown service.
🌿 The Gentle Awakening
This is the sort of cyber story that makes security teams sound paranoid until they are proven merely underfunded. Hotels are perfect espionage habitats. They concentrate executives, diplomats, consultants, contractors, defense-adjacent employees, and conference attendees into a temporary trust environment operated by networks that are often optimized for room numbers, not nation-state adversaries.
The cleverness is not that attackers invented some exotic new physics. It is that they targeted the seam where convenience, travel fatigue, and institutional trust meet. A captive portal already interrupts your connection. A fake update screen already feels plausible because modern software has trained users to obey random rectangles. A Microsoft login prompt is so common that many workers treat it like digital wallpaper.
Attribution also carries its own velvet complication. ReliaQuest reportedly said the tactics resembled APT28, also known as Fancy Bear or Forest Blizzard, while Microsoft attributed the operation to Storm-2945 within Midnight Blizzard. For most travelers, the practical distinction is less “which Russian intelligence-aligned cluster did this?” and more “why did I type my corporate password into the complimentary breakfast network?”
👑 The Gold-Leaf Reckoning
The premium lesson is unglamorous: treat hotel Wi-Fi as hostile infrastructure wearing a robe. Corporate travelers should prefer trusted mobile hotspots, VPN protections where appropriate, phishing-resistant multi-factor authentication, device compliance checks, and a strict refusal to install “updates” from network pop-ups. Organizations should harden identity systems so a stolen password is not a boarding pass into the company.
Security departments have spent years warning executives not to trust random links. The new problem is that the link may be delivered by the building they are sleeping in, beneath a logo promising hospitality. The lobby has become an access broker. The captive portal has become a velvet rope. And the guest, tragically, remains the guest.
“Welcome to the executive floor; breakfast is from seven to ten, and the Russian intelligence service has thoughtfully prepared your browser update.” — The Slap of Wisdom Department of Travel-Sized Threat Models, checking out under an assumed identity