Microsoft reported a large-scale campaign by Russian hackers to compromise Wi-Fi networks in hotels worldwide
Several variants of malicious software were distributed, including full-fledged remote access Trojans.

Microsoft announced a large-scale cyberattack by Storm-2945 — a subgroup of the Midnight Blizzard (Nobelium) hacking group — aimed at manipulating traffic in hotel sector networks worldwide, writes Current Time.
The campaign to hack Wi-Fi networks in hotels was named CaptiveCrunch. As part of it, hackers used the Adversary-in-the-Middle (AitM) method — a type of 'man-in-the-middle' attack — to redirect users through their controlled phishing infrastructure. Additionally, they distributed malicious software disguised as browser or operating system updates in response to automatic connection requests sent by users' browsers.
According to the company, several variants of malicious software were distributed, including full-fledged Remote Access Trojans (RATs) for Windows, written in Golang.
They allow attackers to collect system information, files, and keystroke data, steal credentials and session tokens, conduct audio and video surveillance, track removable media, and gain remote access to infected systems.
Microsoft notes that Midnight Blizzard is a Russian hacking group linked by the US and UK to Russia's Foreign Intelligence Service.
Comments