Microsoft Threat Intelligence has warned of a campaign tied to the Russia-linked group known as Midnight Blizzard, saying attackers are hijacking hotel and conference centre Wi‑Fi networks around the world. The activity is associated with a method or tool referred to as CaptiveCrunch.
According to the alert, the goal is to collect credentials from guests connecting to compromised wireless networks and then use that access to deliver malware. That makes hotels and event venues a particularly attractive target, because travellers often rely on shared internet connections and may log in quickly without closely checking the network experience.
The reported operation highlights how public and semi-public Wi‑Fi can be turned into an entry point for espionage and cybercrime. By compromising the wireless environment itself, attackers can target many users at once and blend into normal sign-in traffic seen at hotels and conference locations.
The warning adds to broader concerns around Midnight Blizzard, a group long linked to Russian intelligence interests. In this case, Microsoft’s notice points to a global threat aimed at travellers and business visitors, with stolen credentials and malware delivery at the centre of the campaign.