Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware
- Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centers
- Victims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malware
- CornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokens
Threat actors are taking over Wi-Fi networks in hotels and conference centers and using the log-in portals to steal credentials and deploy information-stealing malware, experts have claimed.
Researchers from Microsoft have published a new report outlining how they spotted Russian state-sponsored actors, known as Midnight Blizzard or APT29, attacking captive portal equipment – networking hardware and software that manages the login page users see before accessing public Wi-Fi.
When connecting to a hotel network, users are often redirected to a page where they must enter their room number, accept the terms of service, and click “Connect” – that redirection is handled by the captive portal.
Latest Videos FromTechRadar
CornFlake and CocoShell
Microsoft did not explain exactly how this gear is attacked. However, when users try to log in on compromised networks, they may be redirected to a fake Microsoft 365 login portal that steals their credentials.
They may also be redirected to device code phishing pages abusing Microsoft Entra ID authentication flows. Finally, the researchers also saw the captive portals being used to display fake browser and OS update pages that trick victims into downloading infostealers.
So far, MIcrosoft found two malware variants being distributed: CornFlake, and CocoShell.
CornFlake acts as an infostealer capable of grabbing keystrokes and clipboard, running remote shell access, grabbing screenshots, using the microphone and the webcam, stealing browser credentials and cookies, exfiltrating files, and more. It presents itself as a “Cloud Sync Service” while using multiple persistence mechanisms.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
CocoShell, on the other hand, is an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.
APT29 is one of the most documented state-sponsored threat actors out there. It’s been active for years and is well-known for its links to Russia’s Foreign Intelligence Service and notable attacks on high-ranking western targets, such as US and German Government officials, as well as SolarWinds and Microsoft.
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centers Victims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malware CornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokens Threat actors are taking over…
Recent Posts
- How to watch Brighton vs Arsenal: Live streams, TV channels for Premier League 2026/27
- Tired of Cluttered Productivity Apps? This One’s Just a Text Document
- MobLand season 2 cast confirm ‘comfortable’ onset dynamic after apparent Tom Hardy rumors cast doubt over season 3 — ‘we’re all pals’
- After a month testing Bose’s new premium headphones, I would recommend them — but I’d recommend waiting more
- The Withings BodyScan 2, complete with cabled handle and premium build, might be the best smart scale of 2026
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023