Microsoft has warned that hotel, conference, and other hospitality Wi-Fi networks are being actively abused by a Russian group to target travelers worldwide. The campaign, dubbed “CaptiveCrunch” turns a routine Wi-Fi login moment into an opportunity to compromise corporate accounts and devices.
From the user’s perspective, nothing looks out of the ordinary: they connect to hotel Wi-Fi, get the usual captive portal prompt, and perhaps see a familiar‑looking message about needing to update something before they can browse. However, behind the scenes, the allegedly state-linked group position themselves in the network path and manipulate DNS (Domain Name System) and HTTP traffic from captive‑portal Wi-Fi.
From there, several things can happen:
- Logins are stolen: The user’s browser session is redirected to attacker‑controlled phishing pages, like fake Microsoft login prompts, where credentials, device codes, or OAuth tokens are harvested.
- Malware is downloaded: The user is presented with fake update or ClickFix dialogs that download malware. In these cases, usually a remote access trojan (RAT) plus an infostealer.
- A machine-in-the-middle attack (MitM) where traffic is quietly proxied through attacker infrastructure, putting the user in a position for further credential theft.
Reportedly, one of the main malware strains used in these attacks is called CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes.
The infostealer was identified as ChocoShell, a fileless Powershell-based information stealer which primarily goes after browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems.
Microsoft lists a set of fake dialogs that may appear once you connect to compromised Wi‑Fi:
- winupdate: A bogus Windows Update window with “Working on updates… Don’t turn off your computer.”
- defender: A fake Windows Security virus scan.
- directx: “DirectX End‑User Runtime Web Installer.”
- vcredist: A Microsoft Visual C++ redistributable installer.
- sysopt: A disk optimization utility.
- netfix: A Windows Network Diagnostics ‘fix’ tool.
- browser: A browser update prompt.
- pdfview: A document/PDF viewer installer.
How to stay safe
Malwarebytes has long warned about the safety of public Wi-Fi. Here’s how you can stay safe while traveling:
- Use your own phone’s hotspot instead of using the public Wi‑Fi. A mobile connection, especially with an eSIM and a reputable carrier, significantly reduces the likelihood of an attack compared to an unknown hotel network.
- If you’re forced to use public Wi‑Fi, use a VPN with an active Kill Switch: Complete the authentication on the hotel portal first, then launch your VPN before opening any website or app. The Kill Switch feature will instantly block all internet traffic if the VPN disconnects even for a second, preventing cybercriminals from injecting malicious code out in the open. While CaptiveCrunch operates around captive portals and pre‑VPN flows, a VPN still reduces other risks and limits passive data collection once you’re online.
- Always inspect the certificate of any public Wi‑Fi login or ‘security’ portal that asks for more than a room number or basic credentials. These aren’t always a straight‑up giveaway, but sometimes they can be an obvious clue: mismatched hostnames, untrusted issuers, or plain HTTP are red flags that should stop you from proceeding.
- Many captive portals ask for an email address for registration or marketing. Even in benign cases, there is little value in handing over your real inbox. If you must provide an address, consider giving a fake one or a throwaway alias that is unrelated to your primary accounts.
- If you are asked to download software, a certificate, a browser update, or a fix tool in order to connect, stop. You should never have to download anything just to log into Wi‑Fi.
- Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy-paste code. Be cautious of pages urging immediate action: sophisticated ClickFix pages add countdowns, user counters, or other pressure tactics to make you act quickly.
- Secure your devices. Use an up-to-date, real-time anti-malware solution with a web protection component.
- Avoid entering Microsoft 365, Google Workspace, or other high‑value credentials directly into any page reached via captive portal redirection. If you need to check corporate mail, follow known URLs rather than clicking through prompts.
And last but not least, update your browser, operating systems, and other important software before you travel. That reduces the chance of getting legitimate update requests while you’re away.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.




