Key Takeaway:
Since May 2026, hackers linked to Russia’s foreign intelligence service have been hijacking the login pages of hotel and conference Wi-Fi. When a guest connects, the page they expect to see is replaced with a fake “update your browser” or “repair your network” prompt that installs spyware, or with instructions to type a code into a real Microsoft page, which hands over the guest’s work account. Microsoft says the campaign resumed on 29 September. Hotel Wi-Fi isn’t unusable, but three habits matter now: never install anything a Wi-Fi login page offers you, never type a sign-in code you didn’t start yourself, and use your phone’s hotspot for anything important.
What Happened
On 31 July 2026, Microsoft Threat Intelligence published details of a campaign it calls CaptiveCrunch. It attributes the campaign to a group it tracks as Storm-2945, which it assesses is part of Midnight Blizzard. That is the Russia-based group the US and UK governments attribute to the SVR, Russia’s foreign intelligence service.
- Where: guest Wi-Fi at hotels and other venues that use a sign-in page, in several countries. Security firm ReliaQuest also found it at conference centres and other shared venues.
- When: Microsoft has seen the activity since early May 2026. It saw the group resume on 29 September and updated its report on 5 October.
- How widespread: Microsoft says the shared equipment and management systems across affected networks suggest access to the services behind many venues, not one-off break-ins. Research from Black Lotus Labs, as reported by GBHackers, linked about 70 affected IP addresses to three North American Wi-Fi providers that serve seven of the ten largest US hotel chains.
- Who they want: corporate travellers, and specifically their work accounts.
Microsoft notes that the technique resembles the router DNS-hijacking operation disclosed in April, when a different Russian group changed the DNS settings on home routers. The idea is the same in both: control the network a person is using, and you control where their browser goes.
How a Hotel Wi-Fi Login Page Works
The page that asks for your room number or surname is called a captive portal. Until you fill it in, the hotel’s equipment holds back your internet access and sends every web request to that page instead.
Your device finds the portal automatically. The moment it joins a network, it quietly asks a known test address whether the internet works. If the answer comes back changed, it assumes there’s a sign-in page and pops it up. That is exactly the moment the attackers used: Microsoft says the fake updates were delivered “in response to automated connectivity checks issued by users’ browsers.”
It’s an ideal spot for an attack for three reasons:
- You expect a page to appear, so a surprise page doesn’t feel suspicious.
- The network is in charge of your traffic until you’re through, including DNS, the system that turns names into addresses. Whoever controls the portal equipment can send you anywhere.
- Your usual protections aren’t running yet. A VPN can’t connect until the portal lets you out.
⚠️ The Three Tricks
| What you see | What it really is |
|---|---|
| “Your browser needs an update”, a Windows Update screen, a virus scan or a “network repair” tool | Spyware. Microsoft’s analysis of the main tool, called CornFlake, lists keylogging, screenshots, microphone and webcam recording, stealing saved browser passwords and cookies, copying files and a remote shell for the attacker. |
| “Verify you’re human: press Win+R, paste this, press Enter” | A trick known as ClickFix. The text you paste is a command that downloads and runs the malware. Copying it in is you installing it. |
| A real Microsoft page at microsoft.com/devicelogin, with a code to type in | Device code phishing. The attacker generated the code. When you enter it and complete your usual two-step sign-in, you approve their session, not yours, and they get into your Microsoft 365 account. |
The third trick is the one that catches careful people, because the page really is Microsoft’s. Device codes exist for things like smart TVs and games consoles that can’t show a normal sign-in page: the TV displays a code, and you type it on your phone. The rule that keeps you safe is simple: only ever enter a device code that a screen in front of you displayed because you asked it to. A Wi-Fi page, an email or a message has no business giving you one.
Microsoft also found landing pages telling Android users to download and install an app file (an APK) directly. That is never a step in connecting to Wi-Fi.
Is Hotel Wi-Fi Safe Now?
For most guests, the honest answer is: safe enough for ordinary browsing, if you treat the sign-in page as untrusted. This campaign is espionage aimed at people with valuable work accounts, not a sweep of every guest’s holiday photos. But the method is now public and simple, the equipment involved serves very large hotel chains, and criminal groups copy techniques that work.
Microsoft’s own advice is blunt: treat hotel, conference, airport and other guest networks as untrustworthy, and prefer your own connection, meaning a phone hotspot or cellular data, whenever practical.
🛡️ How to Stay Safe on Hotel Wi-Fi
- Use your phone’s hotspot for anything important. Work email, banking and anything you sign in to. Mobile data doesn’t pass through the hotel’s equipment at all.
- Never install anything a Wi-Fi page offers you. Not a browser update, not a “security tool”, not a certificate, not a network fixer. Real updates come from your device’s own settings: Windows Update, Software Update on a Mac or iPhone, Settings or the Play Store on Android. If you’re unsure, close the page and check there.
- Never paste a command a website gives you. No real login page asks you to press Win+R, open PowerShell or paste anything into a terminal.
- Never type a device code you didn’t start. If a page sends you to microsoft.com/devicelogin or any similar “enter this code” page, close it.
- Give the portal as little as possible. A room number and surname is normal. Your work email and password are not. Microsoft specifically advises against reusing work credentials on guest-network sign-up pages.
- Once you’re through, switch your VPN on, before you open email or anything else. More on what that does and doesn’t protect below.
- Never click past a certificate warning. If your email or bank suddenly shows a “your connection is not private” page on hotel Wi-Fi, stop and disconnect. That warning is your browser catching a fake server.
- Forget the network when you check out, so your laptop doesn’t rejoin it automatically next time, or at another hotel with the same network name.
If your work offers passkeys or a physical security key, set them up before you travel. Microsoft recommends passwordless sign-in methods, and a passkey can’t be phished into a fake page the way a password can.
Does a VPN Protect You?
Partly, and it’s worth being precise about which part.
| Stage | Does a VPN help? |
|---|---|
| The sign-in page itself | No. The VPN can’t connect until the portal lets you out, so whatever the portal shows you, you see. |
| A fake update or pasted command | No. If you run the malware, it runs. No network tool can undo that choice. |
| Everything after you’re connected | Yes. Your traffic, including DNS lookups, goes through an encrypted tunnel the hotel’s equipment can’t read or redirect. Redirecting your lookups is how this campaign sent people to its pages; inside the tunnel, that stops working. |
That third row is why Microsoft advises companies to use travel routers or hotspots “that establish encrypted tunnels back to trusted corporate infrastructure.” For personal devices, a paid VPN does the same job for your own traffic. If you don’t have one, PureVPN is one option, and our guide on how to compare VPNs covers what to check before choosing any provider. Turn on its kill switch, so nothing slips out if the connection drops, and run a VPN leak test once you’re connected to confirm your traffic really is going through it.
How to Spot the Fake Domains
Microsoft’s latest indicators include addresses chosen to look like routine background traffic: cdn-gstat[.]com (Google’s real domain is gstatic.com), sslcdnhost[.]com and network-privacy[.]com. None of them would look odd in a browser bar at a glance, which is the point.
If a page you didn’t expect claims to belong to Microsoft, Google or your hotel, look at the address. Then check who registered it and when with a WHOIS lookup. A “Microsoft” domain registered a few weeks ago, by someone who isn’t Microsoft, answers the question.
If You Think You Clicked
- Disconnect from the Wi-Fi.
- If it’s a work device, tell your IT team now. Microsoft has published detections for this campaign, and they will want to know which network you were on.
- Run a full antivirus scan. On Windows, that’s Windows Security → Virus & threat protection → Scan options → Full scan.
- Change your passwords from a different, clean device, starting with email. The malware steals saved browser passwords, so assume they’re known.
- Sign out of every session. Stolen cookies and tokens let an attacker stay signed in without your password. Your Microsoft, Google and Apple account security pages each have an option to sign out everywhere, and a list of signed-in devices to check.
- If you entered a device code, treat the account as compromised: change the password, sign out everywhere, and check the account’s list of devices for one you don’t recognise.
FAQ
Can a hotel Wi-Fi page infect my laptop just by opening?
Not in what Microsoft describes. Every route in this campaign needs you to do something: download and run a fake update, paste a command, or type in a code. That’s the good news, because it means saying no works.
Is airport and café Wi-Fi the same?
Any network with a sign-in page works the same way, and Microsoft’s advice covers airports and conference venues too. This campaign was found mainly at hotels, but the habits above apply to every guest network.
Are phones safe?
The malware Microsoft analysed targets Windows, but some landing pages told Android users to install an app file directly, so phones aren’t off the table. On any phone, refuse app installs from web pages and only install from the official app store.
Is a free VPN good enough for hotel Wi-Fi?
Some are worse than nothing, because you’re simply moving your trust from the hotel to an unknown company that has to pay its bills somehow. Our article on whether free VPNs are safe explains what to watch for.
Does HTTPS protect me on hotel Wi-Fi?
It protects what you send to a real site, and it’s why a fake server can’t silently impersonate your bank: your browser shows a warning. It doesn’t stop you running a fake update or typing a code into a real page, which is why this campaign relied on those. More in our guide to how HTTPS works.
The Short Version
A hotel Wi-Fi sign-in page is a stranger’s computer standing between you and the internet, and this year some of them were hostile, reached through providers that serve some of the biggest hotel chains in the US. Use your phone’s hotspot when it matters. Never install, paste or type a code because a Wi-Fi page asked you to. And switch your VPN on as soon as you’re through the sign-in page.
Sources
- Microsoft Threat Intelligence — CaptiveCrunch: Midnight Blizzard targets travelers worldwide (31 Jul 2026, updated 5 Oct 2026)
- GBHackers — Midnight Blizzard uses captive portals to deliver CornFlake RAT (6 Oct 2026), reporting the Black Lotus Labs findings
- Infosecurity Magazine — Midnight Blizzard targets travelers via captive portals