Connecting to hotel Wi-Fi could expose your data to hacking! Microsoft warns

Microsoft Alert: In this attack, the fraudsters targeted this system. It should be noted that in some cases, attackers can also manipulate the network's DNS and HTTP traffic.

 

(Connecting to the hotel's Wi-Fi will drain your phone's data.)

Microsoft Alert: The internet has become a necessity. Therefore, it's often seen that when people visit a hotel, they start using the free Wi-Fi available there. It's worth noting that in this technological world, cyber criminals have also become quite advanced. They are using new methods to defraud people. In this context, Microsoft has issued an important warning for hotel visitors.

Microsoft's warning

According to media reports, Microsoft revealed a cyberattack campaign called CaptiveCrunch in a report released on July 31. According to the company, cyber attackers are taking over the sign-in systems of hotel and conference center Wi-Fi networks. Users connecting to the networks are then presented with fake software updates and fake login pages.

 

 

Hotel Wi-Fi sign-in page targeted

According to information, whenever you check into a new hotel and connect to its Wi-Fi, you'll first see a login page with an option to accept the terms and conditions. This is called the Captive Portal.


 

Now, according to Microsoft, this attack targeted this very system. It's worth noting that in some cases, attackers can even manipulate the network's DNS and HTTP traffic. This means that the attackers can redirect a user to a different website or page than the one they intended to visit.

Fake Microsoft login can also lead to fraud.

For your information, another method used by attackers is to obtain a user's login credentials and session by creating a genuine Microsoft sign-in page.

Microsoft has also noticed pages since July 16 that direct users to Device Code Authentication. This is a legitimate Microsoft login feature, but attackers are exploiting it.

The most dangerous thing about this is that the Microsoft website where the user enters the code is completely genuine. However, the code entered by the user is initiated by the attacker. This is why this method of attack appears more advanced than other methods.

AI is also being used

According to Microsoft, Storm-2945 has been using AI in its cyber operations since February, including technologies such as Device Code and OAuth-based phishing.

The company says that AI was used to assist in a significant part of the group's work, although Microsoft did not clarify which AI systems were used or what tasks were automated.

What can happen after malware is installed?

If the user executes software or commands provided by the attacker, their data may be exposed. According to Microsoft, attackers can perform a variety of activities on the infected device.

  • Recording information typed on the keyboard
  • Taking a screenshot
  • Recording audio and video
  • Stealing browser cookies
  • Retrieve saved passwords
  • Monitoring USB drive activity
  • Executing remote commands via PowerShell or Command Prompt
  • Route internet traffic through a proxy you control

In this way, the attacker is not limited to just one device but can also access the accounts and other important information associated with it.

Android users should also be careful

It's worth noting that this isn't just dangerous for Windows users, but it could also affect Android users. In fact, some ClickFix pages even ask Android users to download and install an APK file from outside. However, according to Microsoft, the tools used for Android are currently less active than the Windows version.


 

What to do when using hotel Wi-Fi

It's worth noting that hotel Wi-Fi has become an easy target for cyber criminals these days. Therefore, to prevent cyberattacks in hotels, it's important to keep a few important things in mind. Where possible, use a personal mobile hotspot. This significantly reduces the risk of attackers connecting to the hotel's Wi-Fi network.

Additionally, if you must use guest Wi-Fi, using a VPN is a good option. Also, don't accept any unknown downloads or installations that appear on the Wi-Fi's captive portal.