Microsoft has uncovered a new cyber espionage campaign in which attackers are targeting hotel and conference center Wi-Fi networks to steal Microsoft 365 accounts. The company has linked the operation to the Russian state-backed threat group Midnight Blizzard, also known as APT29 or Cozy Bear. According to Microsoft’s threat intelligence team, the campaign has been active since May 2026 and mainly targets people who travel frequently for work.

Instead of sending phishing emails, the attackers first compromise the network equipment that controls hotel Wi-Fi login portals, also known as captive portals. Once they gain access, they manipulate internet traffic using DNS poisoning and HTTP redirection. This allows them to silently redirect victims away from legitimate Microsoft 365 login pages and onto fake websites that look almost identical to the real ones.
When a guest connects to the hotel Wi-Fi and attempts to access Microsoft 365 services, the fake login page asks them to enter their credentials. The website is carefully designed to appear genuine, making it difficult for users to notice anything suspicious. As soon as the victim signs in, the attackers capture usernames, passwords, and authentication tokens that can later be used to access corporate Microsoft 365 accounts.

Microsoft also found that the attackers use a custom malware family called CornFlake during the campaign. This malware is delivered through the compromised Wi-Fi infrastructure and helps the attackers maintain access to infected devices while collecting sensitive information. By combining fake login pages with custom malware, the attackers increase their chances of successfully stealing valuable corporate data.
The campaign mainly targets business travelers, including executives, legal professionals, government officials, financial experts, and employees from organizations that rely heavily on Microsoft 365. Since these users often connect to public Wi-Fi while travelling, they become attractive targets for cyber espionage. Microsoft believes the operation is focused on collecting intelligence rather than carrying out financial fraud.

Researchers say the attackers compromise network gateways rather than individual devices at first. By controlling the Wi-Fi login process, they can intercept traffic before users even reach the websites they intended to visit. This technique makes the attack much harder to detect because victims believe they are simply connecting to a normal hotel internet service while the malicious activity happens in the background.
Microsoft has advised organizations and travelers to remain cautious when using public Wi-Fi networks, especially in hotels and conference venues. Users should verify website addresses before entering credentials, avoid ignoring browser security warnings, and use stronger authentication methods wherever possible. Organizations are also encouraged to monitor unusual Microsoft 365 login activity and strengthen identity protection measures.

This campaign highlights how cybercriminals are moving beyond traditional phishing emails and exploiting trusted public infrastructure to steal corporate accounts. By taking control of hotel Wi-Fi networks and using custom malware alongside fake Microsoft 365 login pages, the attackers have created a sophisticated attack chain that is difficult for ordinary users to recognize. The discovery serves as an important reminder that even trusted public internet connections can become a serious cybersecurity risk.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news