Microsoft is sounding the alarm about a suspected Russian hacking group that has been hijacking Wi-Fi at various hotels to steal passwords and spread malware.
The company is responding after cybersecurity vendor ReliaQuest discovered Wi-Fi gateways at hotels and conference centers in multiple US cities and abroad had been tampered with to redirect users to secretly malicious websites to steal logins for Microsoft 365 portals.
Microsoft confirmed the compromised Wi-Fi gateways are sending users to “doppelganger domains mimicking Microsoft online services” to steal login details. But the hijacked Wi-Fi has also been funneling malware to affected users, disguising them as browser or OS updates.
“Multiple variants have been delivered, including fully-featured Windows remote access trojans,” Microsoft’s report warned, noting the malware can collect passwords, steal files, and let a hacker secretly hijack and monitor their PC.
(Credit: Microsoft)
The compromised Wi-Fi systems will deliver malware via a trap called ClickFix, or a fake website that tries to trick you into executing malicious instructions. ClickFix can sometimes dupe a user because the websites are dressed up to look like a legitimate CAPTCHA page or an update process that’ll ask you to complete extra steps to finish. But in reality, running the instructions will download and execute malware.
In its report, Microsoft included screenshots showing how compromised Wi-Fi systems delivered a ClickFix attack that pretended to be a Windows Driver Repair Utility, and another that was a fake Google “Verify It’s You” test.

(Credit: Microsoft)
One of the malware attacks has been dubbed “Cornflake” and can pose as a Windows update, Windows Security virus scan, a document viewer installer, and a browser update, among other things. “It displays a convincing fake progress window designed to occupy the victim’s attention while the binary copies itself to %APPDATA%\svchost32\svchost32.exe and establishes persistence,” the company says.

(Credit: Microsoft)
In addition to Windows PCs, the attacks can target Android devices via APK files delivered through similar ClickFix-style screens.
Recommended by Our Editors
ReliaQuest suspected the hacks involved the Russian state-sponsored group APT 28 or Fancy Bear. However, Microsoft links the Wi-Fi tampering to a subgroup of another Russian cyberespionage outfit, APT 29 or Cozy Bear, although both are linked to the Kremlin.
Microsoft is advising users to “minimize trust in hospitality and guest networks” and to consider relying on their own cellular data rather than a hotel’s Wi-Fi. “Avoid downloading software updates, certificates, browser updates, network troubleshooting tools, or security utilities presented through captive portals or other unexpected web prompts,” the company adds.
ReliaQuest has also said that activating a VPN in full-tunnel mode on their computers can block a compromised Wi-Fi gateway from redirecting web visits to malicious domains. ReliaQuest also says with “low-to-medium confidence” that the hacker likely staged the attacks by accessing the remote management interfaces for the Wi-Fi equipment, which can be secured with weak or known passwords.
About Our Expert

Michael Kan
Principal Reporter
Experience
I’ve been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I’m currently based in San Francisco, but previously spent over five years in China, covering the country’s technology sector.
Since 2020, I’ve covered the launch and explosive growth of SpaceX’s Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I’ve combed through FCC filings for the latest news and driven to remote corners of California to test Starlink’s cellular service.
I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.
I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I’m now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I’m always eager to learn more, so please jump in the comments with feedback and send me tips.
Click Here For The Original Source.
