Blog

Hotel Wi‑Fi Under Attack: How Hackers Are Turning Your Travel Connection Into a Malware Trap

Published August 7th, 2026 by Bayonseo

When traveling, the free hotel Wi-Fi that you depend on for work could be a sneaky trap. Travelers are being alerted by Microsoft security researchers about a sophisticated worldwide effort called CaptiveCrunch, in which Russian state-sponsored hackers take over hotel and conference center Wi-Fi networks in order to steal login credentials and infect devices with harmful software.

The infamous Midnight Blizzard (APT29) group has been identified as the attackers who are breaching the captive portal equipment, which is what you see when you connect to hotel Wi-Fi. Through DNS and HTTP traffic manipulation, they can mislead users into downloading malware using a technique called ClickFix, present phony browser or operating system upgrades, or reroute unwary passengers to phishing pages that mimic Microsoft 365 login gateways.


The Malware Arsenal: CornFlake and ChocoShell

One of two unique malware families is used by the attackers once a device has been compromised:

  • CornFlake is a potent remote access trojan (RAT) based on Go that allows hackers to take almost total control of a compromised system. Among its abilities are:
  • Keylogging, clipboard monitoring, and remote shell access
  • Monitoring using webcam and microphone
  • Theft of Microsoft 365 session tokens, cookies, and browser credentials
  • System reconnaissance and file exfiltration
  • CornFlake uses several persistence techniques, such as a watchdog routine that restores itself if it is removed, and poses as a genuine Windows component known as "Cloud Sync Service" in order to evade detection.

The second payload, ChocoShell, is an in-memory PowerShell credential stealer that targets WiFi credentials, Microsoft 365 and Azure AD tokens, stored passwords, and browser cookies. According to Microsoft, both malware families were probably created using AI technologies, underscoring the increasing sophistication of state-sponsored cyberthreats.


Why This Matters for Travelers

Since at least early May 2026, the CaptiveCrunch campaign has been running, and it is thought to be quite focused and extensive. It is especially dangerous since the attackers can launch an attack by compromising the network infrastructure itself, intercepting any passenger who connects, rather than having to infiltrate individual devices. Your credentials and private information are vulnerable whether you work remotely, are a company leader, or are on vacation for pleasure.


How to Protect Yourself

Microsoft advises against using conference and hotel Wi-Fi as unreliable. To be secure:

  • For all sensitive work, use a managed VPN or a private cell phone.
  • Steer clear of using public WiFi to access sensitive data or log into business accounts.
  • Any login page that comes outside of the typical flow of your browser should raise suspicions.
  • Never use a hotel's Wi-Fi portal to download "updates"
  • Turn on multi-factor authentication to increase security.


How Bayon Technologies Group Can Help

We at Bayon Technologies Group are aware that contemporary travel poses particular cybersecurity threats. With solutions like secure VPN deployments, endpoint protection, and thorough security awareness training to help staff identify and steer clear of complex assaults like CaptiveCrunch, we assist businesses in safeguarding their remote workforce. Get in touch with us right now to make sure your staff is safe while working or traveling.


‹ Back