Russia State-Sponsored Hackers Turn Hotel and Conference Wi-Fi Networks Into Malware Delivery Systems
Microsoft has identified a Russian state-sponsored hacking group, Storm-2945, that is compromising public Wi-Fi at hotels and conference centers. The attackers use these networks to intercept traffic and deploy malware to steal corporate credentials from travelers.
Why it matters
This highlights a significant vulnerability for business travelers and underscores the evolving sophistication of state-sponsored cyberespionage targeting corporate infrastructure.
Russian state backed hackers are compromising public Wi-Fi infrastructure at hotels, conference centres and other shared venues to intercept travellers’ internet traffic, distribute remote-access malware and steal access to corporate cloud accounts, according to new research from Microsoft.
The campaign, which Microsoft calls CaptiveCrunch , has been attributed to Storm-2945, an operational subgroup of Midnight Blizzard—the long-running cyberespionage operation also known as APT29, Cozy Bear and Nobelium. The United States and United Kingdom have previously linked Midnight Blizzard to Russia’s Foreign Intelligence Service, the SVR.
Microsoft said it began observing Storm-2945 manipulating traffic from captive-portal networks in early May 2026, although associated OAuth and device-code phishing activity dates to February. The operation appears primarily designed to compromise corporate travellers who connect their work devices to wireless networks in hotels, conference venues and similar locations.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in