Russian Intelligence Hackers Capture Captive Portals
Hackers are using hotel Wi-Fi networks across the United States, India and Saudi Arabia to steal credentials, exfiltrate data and spread malware onto personal devices, according to Microsoft and ReliaQuest.
See Also: From Maps to Mission: Turning Geospatial Data into Real-time Action
Microsoft’s threat intelligence arm began tracking the threat in early May, attributing activity to the Storm-2945 sub-cluster of Midnight Blizzard. As part of Russia’s Foreign Intelligence Service, the cyberespionage group is also commonly tracked as APT29, Cozy Bear or BlueBravo.
According to Microsoft, Storm-2945 is now carrying out “widespread but targeted traffic manipulation” campaigns on the hospitality industry’s networks, which operate captive portals, leading Microsoft to dub the campaign “CaptiveCrunch.”
Microsoft drew on July research from ReliaQuest, which tracked DNS poisoning attacks on hotel Wi-Fi networks attributed to Unit 26165 of the Russian Main Intelligence Directorate, often known as APT28, Forest Blizzard and Fancy Bear. Microsoft researchers said the campaigns share tradecraft and “TTP similarities,” but said CaptiveCrunch is the work of a different threat actor.
Based on reports from Microsoft and ReliaQuest, hackers are compromising hospitality captive portal infrastructures to carry out adversary-in-the-middle campaigns, which redirects victims to one of two mimicked attack chains: a fake Microsoft authentication page or a fake browser software update page, with the goal being credential theft or malware delivery. ReliaQuest assessed hackers likely are able to access the devices through management interfaces exposed to the internet.
Microsoft identified two malware payloads distributed in the attacks: the Cornflake persistent remote access Trojan and the ChocoShell infostealer, which harvests and extracts user credentials and authentication tokens.
Conference centers and other shared corporate venues have also been attacked, said ReliaQuest. Additionally, Microsoft said Storm-2945’s “consistent coding standard and descriptive commentary” may be watermarks of artificial intelligence tool usage for campaign support or code generation.
Researchers encourage corporate travelers bound for professional conferences or upcoming hotel stays to verify all URLs before inputting personal or company credentials, utilize personal VPNs on public Wi-Fi networks or to rely on “mobile hotspots, satellite and eSIM-based cellular data connections,” making sure to avoid random software updates or downloads initiated through captive portals.
For hospitality providers themselves, hotels, conference centers and airports should look to secure network infrastructures while monitoring both DNS settings and gateway devices.
Click Here For The Original Source.
