Microsoft has announced that a Russian state-sponsored cyber espionage group has launched a sophisticated campaign that compromises legitimate hotel and travel Wi-Fi login systems to steal credentials and deploy malware against travelers worldwide.
U.S. intelligence and law-enforcement agencies under the Trump administration have previously sounded the alarm over such cyber and influence threats and continue to identify Russia as a source.
Rather than creating fake wireless networks or phishing pages that users might recognize as suspicious, the attackers exploit trusted infrastructure already operated by hotels and other travel venues, according to Microsoft’s report.
Microsoft’s researchers say the attackers are compromising the legitimate captive portals used by hotels and other hospitality providers, unlike traditional attacks that rely on fake Wi-Fi hotspots or counterfeit login pages. As a result, travelers may unknowingly connect to authentic Wi-Fi networks while having their traffic manipulated behind the scenes.
According to Microsoft, the Russia state-sponsored campaign has been designed to steal Microsoft 365 credentials, deliver malware to Windows devices, and collect intelligence from targeted organizations. The company said attackers use adversary-in-the-middle phishing techniques and abuse Microsoft’s device code authentication process to convince victims to authorize access to their accounts.
Once access is obtained, the attackers can potentially maintain long-term access to email, cloud services, and other Microsoft 365 resources. In some cases, Microsoft says victims may also receive malware capable of stealing browser cookies, authentication tokens, saved credentials, and other sensitive information while providing attackers with persistent remote access.
Microsoft said it is urging organizations to use various strategies to strengthen identity protections. This includes deploying phishing-resistant multi-factor authentication, monitoring for suspicious device registrations, and securing captive portal infrastructure against compromise.
For travelers, the company recommends they remain cautious of unexpected Microsoft authentication prompts while using public Wi-Fi, enable phishing-resistant MFA such as passkeys or hardware security keys, consistently keep devices updated, and use only trusted VPN services.
