Cookie Consent by Free Privacy Policy Generator

Russian State-Linked Group Targets Travellers Through Hotel Wi-Fi Networks

Infosecurity Magazine reports that Midnight Blizzard, a Russian state-linked advanced persistent threat group, has been observed hijacking hotel captive portals to deliver fake software updates and steal authentication tokens from travellers. The campaign, attributed to the sub-group Storm-2945, involved compromising the Wi-Fi login pages used by hotels and other hospitality venues to push malicious updates that appeared legitimate. Once installed, the malware harvested session tokens, credentials and other authentication material from victims' devices. The targeting of travellers, particularly those likely to be business users or government officials, reflects a deliberate focus on individuals who may have access to sensitive organisational systems and are more likely to connect to unfamiliar networks while away from their usual security controls. This type of attack exploits the trust users place in hotel Wi-Fi networks and the common practice of accepting software updates without careful verification.

Why this matters for UK organisations

This campaign highlights the risks associated with remote and mobile working, particularly for employees who travel frequently or work from locations outside direct IT control. Hotel Wi-Fi networks, airport lounges and other public or semi-public internet access points are attractive targets for threat actors because they sit outside organisational security boundaries and users are often less cautious about the networks they join. The use of fake update prompts is a well-established social engineering technique, but the compromise of captive portals adds a layer of apparent legitimacy that makes the attack harder to detect. This type of threat is difficult to defend against through technical controls alone and requires a combination of user awareness, endpoint security, network segmentation and clear policies about how employees should connect to untrusted networks. For organisations with employees who travel internationally or work remotely, this represents a material risk that requires both technical and behavioural controls.

What to review

Organisations should review how travelling employees are supported and protected when working remotely. Consider whether endpoint security controls are effective on untrusted networks, whether users understand the risks of public Wi-Fi and fake update prompts, and whether VPN or zero-trust access controls are in place to limit exposure when employees connect from outside the corporate network. Review whether software updates are managed centrally and whether users are trained to recognise and report suspicious update prompts. Consider whether authentication tokens and session credentials are protected by multifactor authentication, short expiry times and conditional access policies that limit their use from untrusted locations. Organisations should also review whether there is clear guidance for employees about how to connect securely when travelling, and whether IT support is available to help employees verify the legitimacy of network access points and software updates.

Source: Infosecurity Magazine

News and blog posts
Infosecurity Magazine reports that Midnight Blizzard, a Russian state-linked...
Today's brief highlights the operational realities of modern security risk...
The Guardian reports that UK Government Investments (UKGI), the public body...
TechCrunch reports that OpenAI and Anthropic have disclosed that their...