Hotels and conference centers worldwide are under attack by a sophisticated cyber campaign that exploits vulnerabilities in their Wi-Fi networks. The attackers, linked to the Russian threat actor Midnight Blizzard, use custom malware to breach Microsoft 365 accounts, raising serious concerns about data security.
At the center of this operation is a manipulation of DNS settings on hotel and conference Wi-Fi networks, allowing the attackers to intercept user connections and redirect victims to phishing pages that impersonate Microsoft 365 login portals. This tactic has been active since at least early May, with evidence suggesting that the threat actor has been running device and OAuth code phishing operations since February.
The attackers use two custom malware families: CornFlake, a Go-based remote access trojan (RAT), and ChocoShell, an in-memory PowerShell credential stealer. These tools allow for persistent access, credential theft, surveillance, and data exfiltration. According to Microsoft’s analysis, the malware can disguise itself as legitimate Windows components or browser updates, making it difficult for users to detect.
The attackers’ modus operandi involves modifying DNS settings on captive portal equipment to redirect user connections to phishing pages. This allows them to steal Microsoft 365 accounts and gain access to sensitive data. A third option not previously disclosed involves using fake browser and operating system update pages that deliver malware to Windows via ClickFix prompts for user verification.
Microsoft has identified signs of breaches in shared infrastructure rather than isolated devices, suggesting that the attackers have a sophisticated understanding of network architecture. The company recommends treating hotel and conference Wi-Fi as untrusted, using private cellular or managed connections whenever possible, and avoiding software updates or tools offered through captive portals.
The use of AI tools to develop these custom malware families raises serious concerns about the sophistication and adaptability of cyber threats. It’s essential for organizations and individuals to be vigilant when connecting to public Wi-Fi networks and to take steps to protect their data.
In light of this attack, it’s crucial to remember that hotels and conference centers are not secure environments. Users should assume that any software updates or tools offered through captive portals may be malicious. To avoid falling victim to these attacks, users should adopt phishing-resistant authentication with MFA and passkeys, disable Microsoft Entra device code authentication when not needed, and avoid using corporate credentials to register for guest Wi-Fi networks.
Ultimately, this campaign serves as a reminder that cyber threats are becoming increasingly sophisticated and targeted. It’s essential for individuals and organizations to stay informed about the latest threats and take proactive steps to protect themselves.
Source: Bleeping Computer — 2026-08-04