{"id":10578,"date":"2026-08-10T02:51:06","date_gmt":"2026-08-10T02:51:06","guid":{"rendered":"https:\/\/koshalsambada.in\/?p=10578"},"modified":"2026-08-10T02:51:06","modified_gmt":"2026-08-10T02:51:06","slug":"microsoft-warns-travellers-of-attacks-on-hotel-wi-fi-says-hackers-can-record-your-video-audio-steal-passwords-how-to-know-and-protect-yourself","status":"publish","type":"post","link":"https:\/\/koshalsambada.in\/?p=10578","title":{"rendered":"Microsoft warns travellers of attacks on hotel Wi-Fi; says: Hackers can record your video, audio, steal passwords; how to know and protect yourself"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-133077763,imgsize-789835,width-400,height-225,resizemode-4\/microsoft.jpg\" alt=\"Microsoft warns travellers of attacks on hotel Wi-Fi; says: Hackers can record your video, audio, steal passwords; how to know and protect yourself\" title=\"Microsoft cuts 4800 job\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>Microsoft\u2019s Threat Intelligence team has issued a warning to travelers following a series of sophisticated cyberattacks targeting guest Wi-Fi networks at hotels and hospitality venues worldwide.<!-- --> The internet hijacking campaign, dubbed \u2018CaptiveCrunch\u2019, has been active since at least May and is attributed to Storm-2945, a sub-cluster claimed to be of the Russian hacking group Midnight Blizzard (also known as APT29 or Cozy Bear).<span class=\"id-r-component br\" data-pos=\"3\"\/>According to Microsoft, the hacker group is executing &#8220;widespread but targeted&#8221; traffic manipulation attacks through Public guest networks and captive portal screens \u2013 the web pages that appear when users attempt to log onto hotel Wi-Fi or those at public places like airports, tourists venues and more. <!-- -->&#8220;To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries.<!-- --> ReliaQuest has identified this activity not only at hotels, but also conference centers and other shared venues, and assesses that the goal of this activity is to access the accounts of corporate travelers,&#8221; said Microsoft in its report.<span class=\"id-r-component br\" data-pos=\"10\"\/><\/p>\n<p><h2>How \u2018CaptiveCrunch\u2019 hacker attack works<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"12\"\/>The hackers compromise the underlying Wi-Fi infrastructure of hospitality venues, redirecting unsuspecting guests through fake portals and malicious pop-ups. Once connected, victims are tricked into downloading malicious files or entering sensitive credentials under the guise of routine security checks.<span class=\"id-r-component br\" data-pos=\"14\"\/><\/p>\n<p><h2>Microsoft revealed that the attacks takes place in two primary ways:<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"16\"\/>Fake Browser Updates: Guests attempting to connect to hotel Wi-Fi may be presented with pop-ups prompting them to update their web browser or run network troubleshooting utilities. <!-- -->Some prompts mimic official Google security checks with warnings such as: &#8220;Our systems have detected unusual traffic from your computer network. Please complete the security check to access Google Search.&#8221;<span class=\"id-r-component br\" data-pos=\"20\"\/>Account Takeovers: In other instances, users are redirected to convincing fake login screens. Once credentials are submitted, the attackers gain access to the victim&#8217;s Microsoft 365 accounts, granting them entry to private emails, OneDrive documents, and corporate networks.<span class=\"id-r-component br\" data-pos=\"23\"\/>Once malware is installed on a target device, the hijackers gain broad control. Microsoft warned that Storm-2945 can capture keystrokes, record audio and video, take screenshots, steal browser cookies and stored passwords, and remotely operate the infected device.<span class=\"id-r-component br\" data-pos=\"26\"\/>Microsoft listed a number of potential fake windows that may pop up upon logging into a compromised network, prompting users to download updates or patches. They include:<span class=\"id-r-component br\" data-pos=\"28\"\/>* &#8220;winupdate&#8221;: A Windows Update screen displaying the words &#8220;Working on updates\u2026 Don&#8217;t turn off your computer&#8221;<span class=\"id-r-component br\" data-pos=\"30\"\/>* &#8220;defender&#8221;: A fake Windows Security virus scan<span class=\"id-r-component br\" data-pos=\"32\"\/>* &#8220;directx&#8221;: A &#8220;DirectX End-User Runtime Web Installer&#8221;<span class=\"id-r-component br\" data-pos=\"34\"\/>* &#8220;vcredist&#8221;: A Microsoft Visual C++ 2015-2022 Redistributable installer<span class=\"id-r-component br\" data-pos=\"36\"\/>* &#8220;sysopt&#8221;: A disk optimization utility<span class=\"id-r-component br\" data-pos=\"38\"\/>* &#8220;netfix&#8221;: A false Windows Network Diagnostics tool<span class=\"id-r-component br\" data-pos=\"40\"\/>* &#8220;browser&#8221;: A browser update prompt<span class=\"id-r-component br\" data-pos=\"42\"\/>* &#8220;pdfview&#8221;: A document viewer installer<span class=\"id-r-component br\" data-pos=\"44\"\/><\/p>\n<p><h2>How travelers can stay safe<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"46\"\/>Microsoft urges both individual travelers and corporate IT departments to exercise extreme caution on public networks, recommending the following protective measures:<span class=\"id-r-component br\" data-pos=\"48\"\/>Use Cellular Hotspots: Avoid public or hotel Wi-Fi networks whenever possible; instead, rely on personal cellular hotspots or encrypted private connections.<span class=\"id-r-component br\" data-pos=\"51\"\/>Ignore Unexpected Pop-Ups: Never download browser updates, security tools, network certificates, or software updates offered directly through hotel captive portals or unexpected browser pop-ups.<span class=\"id-r-component br\" data-pos=\"53\"\/>Limit Data Sharing: Companies should review and restrict the sensitive information employees provide to hospitality providers when traveling or logging onto guest networks.<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/microsoft-warns-travellers-of-attacks-on-hotel-wi-fi-says-hackers-can-record-your-video-audio-steal-passwords-how-to-know-and-protect-yourself\/articleshow\/133077739.cms\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft\u2019s Threat Intelligence team has issued a warning to travelers following a series of sophisticated cyberattacks targeting guest Wi-Fi networks at hotels and hospitality venues worldwide. The internet hijacking campaign, dubbed \u2018CaptiveCrunch\u2019, has been active since at least May and is attributed to Storm-2945, a sub-cluster claimed to be of the Russian hacking group Midnight [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":10579,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-10578","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-31"],"magazineBlocksPostFeaturedMedia":{"thumbnail":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","medium_large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","1536x1536":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","2048x2048":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","blogsy-small":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","blogsy-small-tall":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","blogsy-small-square":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","blogsy-small-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","blogsy-medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","blogsy-medium-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","blogsy-large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg","blogsy-wide":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg"},"magazineBlocksPostAuthor":{"name":"admin","avatar":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g"},"magazineBlocksPostCommentsNumber":"0","magazineBlocksPostExcerpt":"Microsoft\u2019s Threat Intelligence team has issued a warning to travelers following a series of sophisticated cyberattacks targeting guest Wi-Fi networks at hotels and hospitality venues worldwide. The internet hijacking campaign, dubbed \u2018CaptiveCrunch\u2019, has been active since at least May and is attributed to Storm-2945, a sub-cluster claimed to be of the Russian hacking group Midnight [&hellip;]","magazineBlocksPostCategories":["\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36"],"magazineBlocksPostViewCount":2,"magazineBlocksPostReadTime":3,"magazine_blocks_featured_image_url":{"full":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg",400,225,false],"medium":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg",300,169,false],"thumbnail":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/08\/1786330267_microsoft.jpg",150,84,false]},"magazine_blocks_author":{"display_name":"admin","author_link":"https:\/\/koshalsambada.in\/author\/admin"},"magazine_blocks_comment":0,"magazine_blocks_author_image":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g","magazine_blocks_category":"<a href=\"#\" class=\"category-link category-link-31\">\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36<\/a>","_links":{"self":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/10578","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10578"}],"version-history":[{"count":0,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/10578\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/media\/10579"}],"wp:attachment":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10578"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10578"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10578"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}