Top News

Hotel Wi-Fi becomes a hacker's weapon! Microsoft alerts travelers; here’s how the spying happens..
Shikha Saxena | August 12, 2026 4:15 PM CST

You need to exercise caution if you use Wi-Fi at hotels or public places. Microsoft has warned travelers about a new cyberattack. In a campaign dubbed "CaptiveCrunch," hackers can redirect users to fake login pages and malicious websites via hotel and other shared Wi-Fi networks. This poses a risk of theft of passwords, accounts, and sensitive information. According to Microsoft, in some instances, attackers can even install malware on the device and gain remote control over it.

**How ​​the cyberattack via hotel Wi-Fi works**
According to Microsoft Threat Intelligence, this attack has been observed targeting hospitality networks since early May 2026. These include Wi-Fi networks at hotels, conference centers, and other public venues where users must log in or accept terms of service before accessing the internet. Attackers can manipulate the DNS and web traffic of such networks. Consequently, users can be redirected to fake Microsoft login pages or malicious websites without immediately realizing it, putting their login credentials and other accounts at risk.

**Hackers infiltrating devices via fake updates**
The group "Storm-2945" is also targeting users through fake software and browser update screens. These screens display prompts claiming that an update for Windows, a browser, security software, or other applications is required for the computer. If a user follows the provided instructions, malicious software may be installed on their device. Microsoft reported that a Windows-based remote access Trojan named "CornFlake"—written in the Go programming language—has also been identified as part of this campaign.

**CornFlake can lead to personal data theft**
The CornFlake malware can grant attackers significant control over an infected computer. According to Microsoft, it can harvest files, passwords, and session-related data; log keystrokes; and monitor connected devices. It can also facilitate audio and video surveillance and provide remote access to the system. To persist on a computer, the malware establishes multiple methods to launch automatically and may even attempt to masquerade as legitimate Windows services and processes.

Android users should also be cautious.
Microsoft has found indications that similar techniques could be used against Android users. Certain malicious pages may prompt Android users to download and install APK files. According to Microsoft, this campaign appears to specifically target corporate travelers, as attackers can gain access to individuals using work-related accounts and devices via hotel and shared Wi-Fi networks. The company has advised travelers and organizations to remain vigilant when using public Wi-Fi and to be wary of unexpected update prompts or login messages. Microsoft is investigating this campaign in collaboration with security partners, including Anthropic and OpenAI.


Disclaimer: This content has been sourced and edited from TV9. While we have made modifications for clarity and presentation, the original content belongs to its respective authors and website. We do not claim ownership of the content.
 


READ NEXT
Cancel OK