Tag: Wi-Fi attacks

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
News

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has connected the Russian threat actor Midnight Blizzard, also known as APT29, to a worldwide campaign that targets Wi-Fi networks in the hospitality industry. The cybersecurity firm ReliaQuest earlier revealed the behavior in a report that described how the attacker altered Wi-Fi device DNS settings in order to obtain Microsoft 365 accounts. In addition to linking the effort to Russian hackers known as Storm-2945, a sub-cluster of Midnight Blizzard, Microsoft discovered two malware families with persistent access, credential theft, surveillance, and data exfiltration capabilities: CornFlake and ChocoShell. Although the threat actor has been conducting device and OAuth code phishing operations since February, Microsoft called the campaign CaptiveCrunch and believes it h...