Russian SVR-Linked Hackers Compromise Hotel Wi-Fi Networks Worldwide for Credential Theft and Espionage
Microsoft reported that Storm-2945, a sub-cluster of the Russia-linked
Storm-2945's use of shared captive-portal infrastructure across hotels and conference venues means remediation cannot proceed property by property; any site sharing the same portal management system stays exposed until the initial access vector is identified. Attributing the campaign to Storm-2945 rather than APT28 recasts it as SVR-directed foreign intelligence collection against traveling officials and executives, a different threat than the GRU-style disruptive access initially suggested. The tactical overlap with Forest Blizzard's router-hijacking operations and shared equipment signatures across venues plausibly point to a common access broker or compromised managed-service vendor rather than direct intrusion into each property. The July 16 addition of device code phishing against Entra ID lets operators hijack an already-MFA-satisfied session without a password, closing only if device code flow is separately restricted beyond standard MFA policy. Sourcing rests on a single primary account, with other outlets republishing without independent corroboration of scope or malware samples.
4 sources
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft -
Microsoft Security Blog - Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware -
The Hacker News - Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says -
The Record - Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens -
Security Affairs