Microsoft: Suspected Russian Hackers Are Targeting Logins Via Hotel Wi-Fi | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Microsoft is sounding the alarm about a suspected Russian hacking group that has been hijacking Wi-Fi at various hotels to steal passwords and spread malware

The company is responding after cybersecurity vendor ReliaQuest discovered Wi-Fi gateways at hotels and conference centers in multiple US cities and abroad had been tampered with to redirect users to secretly malicious websites to steal logins for Microsoft 365 portals.

Microsoft confirmed the compromised Wi-Fi gateways are sending users to “doppelganger domains mimicking Microsoft online services” to steal login details. But the hijacked Wi-Fi has also been funneling malware to affected users, disguising them as browser or OS updates. 

“Multiple variants have been delivered, including fully-featured Windows remote access trojans,” Microsoft’s report warned, noting the malware can collect passwords, steal files, and let a hacker secretly hijack and monitor their PC. 

(Credit: Microsoft)

The compromised Wi-Fi systems will deliver malware via a trap called ClickFix, or a fake website that tries to trick you into executing malicious instructions. ClickFix can sometimes dupe a user because the websites are dressed up to look like a legitimate CAPTCHA page or an update process that’ll ask you to complete extra steps to finish. But in reality, running the instructions will download and execute malware.  

In its report, Microsoft included screenshots showing how compromised Wi-Fi systems delivered a ClickFix attack that pretended to be a Windows Driver Repair Utility, and another that was a fake Google “Verify It’s You” test.  

click fix attack

(Credit: Microsoft)

One of the malware attacks has been dubbed “Cornflake” and can pose as a Windows update, Windows Security virus scan, a document viewer installer, and a browser update, among other things. “It displays a convincing fake progress window designed to occupy the victim’s attention while the binary copies itself to %APPDATA%\svchost32\svchost32.exe and establishes persistence,” the company says.

example of malware

(Credit: Microsoft)

In addition to Windows PCs, the attacks can target Android devices via APK files delivered through similar ClickFix-style screens. 

Recommended by Our Editors

ReliaQuest suspected the hacks involved the Russian state-sponsored group APT 28 or Fancy Bear. However, Microsoft links the Wi-Fi tampering to a subgroup of another Russian cyberespionage outfit, APT 29 or Cozy Bear, although both are linked to the Kremlin. 

Microsoft is advising users to “minimize trust in hospitality and guest networks” and to consider relying on their own cellular data rather than a hotel’s Wi-Fi. “Avoid downloading software updates, certificates, browser updates, network troubleshooting tools, or security utilities presented through captive portals or other unexpected web prompts,” the company adds. 

ReliaQuest has also said that activating a VPN in full-tunnel mode on their computers can block a compromised Wi-Fi gateway from redirecting web visits to malicious domains. ReliaQuest also says with “low-to-medium confidence” that the hacker likely staged the attacks by accessing the remote management interfaces for the Wi-Fi equipment, which can be secured with weak or known passwords.  

About Our Expert





Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW