Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware
- Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centers
- Victims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malware
- CornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokens
Threat actors are taking over Wi-Fi networks in hotels and conference centers and using the log-in portals to steal credentials and deploy information-stealing malware, experts have claimed.
Researchers from Microsoft have published a new report outlining how they spotted Russian state-sponsored actors, known as Midnight Blizzard or APT29, attacking captive portal equipment – networking hardware and software that manages the login page users see before accessing public Wi-Fi.
When connecting to a hotel network, users are often redirected to a page where they must enter their room number, accept the terms of service, and click “Connect” – that redirection is handled by the captive portal.
Latest Videos FromTechRadar
CornFlake and CocoShell
Microsoft did not explain exactly how this gear is attacked. However, when users try to log in on compromised networks, they may be redirected to a fake Microsoft 365 login portal that steals their credentials.
They may also be redirected to device code phishing pages abusing Microsoft Entra ID authentication flows. Finally, the researchers also saw the captive portals being used to display fake browser and OS update pages that trick victims into downloading infostealers.
So far, MIcrosoft found two malware variants being distributed: CornFlake, and CocoShell.
CornFlake acts as an infostealer capable of grabbing keystrokes and clipboard, running remote shell access, grabbing screenshots, using the microphone and the webcam, stealing browser credentials and cookies, exfiltrating files, and more. It presents itself as a “Cloud Sync Service” while using multiple persistence mechanisms.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
CocoShell, on the other hand, is an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.
APT29 is one of the most documented state-sponsored threat actors out there. It’s been active for years and is well-known for its links to Russia’s Foreign Intelligence Service and notable attacks on high-ranking western targets, such as US and German Government officials, as well as SolarWinds and Microsoft.
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centers Victims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malware CornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokens Threat actors are taking over…
Recent Posts
- Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets
- 2026 Lexus ES 500e first drive: A classy sedan with a slow charge
- Apple is working on iPhone-to-Windows copy-paste
- ‘Striking the right balance starts with recognising that every user has different expectations of their browser’: Mozilla’s head of Firefox tells us why the browser is becoming one of the most important layers of the AI era
- Peak Design’s latest bags have clever integrated hooks
Archives
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023