HYPERLINKS: Click Here to Explore Local Websites, Shops & More

Facebook Visit our Facebook Page

Published On: Wed, Aug 5th, 2026

Brits on holiday issued urgent ‘do not use hotel WiFi’ warning | Travel News | Travel


British holidaymakers have been urged to avoid using hotel Wi-Fi after Microsoft revealed that Russian hackers have been hijacking hotel networks to spy on travellers. Russian state-sponsored hackers have been compromising hotel Wi-Fi networks worldwide to steal travellers’ login credentials and infect devices with espionage malware, researchers have found.

In a report published on Friday (July 31), Microsoft said the activity is linked to Storm-2945, a sub-cluster of the Russian espionage group Midnight Blizzard, which Western intelligence agencies believe is connected to Russia‘s Foreign Intelligence Service (SVR). The campaign, first observed by Microsoft in early May, targets hotels and other hospitality venues that require guests to log into Wi-Fi through so-called captive portals – web pages users must access before connecting to the internet.

According to the researchers, the attackers manipulate internet traffic on compromised networks to redirect victims to fake Microsoft login pages or fraudulent browser and operating system update screens designed to deliver malware.

The cybersecurity firm ReliaQuest, which first disclosed the activity in July, said the operation has affected hotels and other hospitality organisations across multiple US cities, as well as in India and Saudi Arabia. The company said conference centres and other shared venues have also been affected, with corporate travellers appearing to be the primary targets.

According to the world’s largest software company, hackers use two main techniques to compromise victims’ devices. First, they use fake Microsoft login pages to steal account passwords. Second, they display fake update warnings that trick users into manually downloading malware onto their devices.

Once installed, this malware operates in two ways. One program, CornFlake, gives hackers full remote control of an infected PC, allowing them to steal files, log keystrokes and record audio or video. The second, ChocoShell, quietly harvests saved passwords, browser cookies, Wi-Fi keys and sign-in tokens.

Microsoft has warned that the operation may already be expanding beyond Windows computers. Some of the fake update pages include instructions directing Android users to download and install a malicious application.

Earlier in April, Britain’s National Cyber Security Centre warned that APT28 hackers had been exploiting vulnerable internet routers to hijack web traffic and conduct espionage by compromising poorly secured or outdated network devices.

Microsoft instead attributed the activity to Storm-2945, which it describes as part of Midnight Blizzard – also known as APT29, Cozy Bear and BlueBravo – an espionage group that primarily targets governments, diplomatic missions and organisations in the defence, energy, media and political sectors in support of Russian foreign policy objectives.

In its own assessment, ReliaQuest warned that any organisation operating captive portal networks, including airports, conference centres, co-working spaces, universities, healthcare facilities and event venues, could also become a target.



Source link

Leave a comment

XHTML: You can use these html tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>