Microsoft Warns of Russian Wi-Fi Attack Targeting Microsoft Accounts

Microsoft is warning about a widespread cyberattack campaign called CaptiveCrunch, in which Russian-linked hackers are exploiting compromised public Wi-Fi networks to redirect users toward fake Microsoft login pages. The campaign is designed to steal account credentials and potentially infect victims’ devices with malware.

Public Wi-Fi Used to Redirect Victims

According to Microsoft, attackers manipulate DNS queries on compromised networks, including Wi-Fi connections in hotels and airports. Users attempting to sign into Microsoft accounts can instead be redirected to convincing phishing pages that imitate Microsoft’s online services.

The attackers can capture device and OAuth codes from these pages, potentially allowing them to take control of Microsoft accounts. Microsoft has been monitoring the campaign since May 2026, following earlier warnings from security researchers.

Malware Can Go Much Further

The campaign reportedly goes beyond credential theft. Microsoft says attackers may install Trojans capable of recording keystrokes, monitoring activity, accessing cameras and forwarding sensitive files and passwords. The malware can also establish remote access, giving attackers continued control over infected devices.

Microsoft is still investigating how the attackers initially compromise public Wi-Fi networks. However, similarities between equipment and management systems across affected networks suggest the campaign could involve shared services within the captive-portal ecosystem rather than isolated attacks on individual venues.

Microsoft attributes the activity to Storm-2945, a group associated with Midnight Blizzard and believed to have links to Russia’s Foreign Intelligence Service.

How to Stay Safe

Microsoft recommends treating hotel, airport, conference and other guest Wi-Fi networks as untrusted. When possible, users should rely on private connections such as their own mobile hotspot.

If public Wi-Fi is unavoidable, using a reputable VPN can add protection by encrypting network traffic. Users should also never download software updates, certificates or applications presented through public Wi-Fi captive portals or unexpected web prompts.

The safest approach is simple: assume public Wi-Fi may not be trustworthy and avoid entering sensitive credentials unless you can verify that the connection and website are legitimate.

Mozilla is discontinuing Pocket and Fakespotmozilla

Mozilla is discontinuing Pocket and Fakespot

permusMayıs 25, 2025
YouTube vows to protect creators from AI fakesyoutube

YouTube vows to protect creators from AI fakes

permusEylül 6, 2024
Get Peace of Mind with a Ring Battery Doorbell, Now 40% Offhome tech

Get Peace of Mind with a Ring Battery Doorbell, Now 40% Off

numan permusŞubat 5, 2025