HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Hotel Wi‑Fi Networks Compromised by Custom Malware, Leading to Microsoft 365 Credential Theft

A Russian‑linked campaign is hijacking hotel Wi‑Fi DNS settings to serve phishing pages that steal Microsoft 365 credentials and deliver custom RATs. The attack highlights gaps in access‑control monitoring that SOC 2 programs must address.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Hotel Wi‑Fi Networks Compromised by Custom Malware, Leading to Microsoft 365 Credential Theft

What Happened – A global campaign dubbed CaptiveCrunch—attributed to the Russian APT29 group—has been hijacking hospitality Wi‑Fi infrastructure. Attackers modify DNS and HTTP traffic on captive‑portal devices, redirecting users to phishing pages that harvest Microsoft 365 credentials or deliver custom Windows malware families (CornFlake, ChocoShell).

Why It Matters for Compliance & Audit Readiness

  • The scenario maps directly to SOC 2 CC6 (Logical Access) and CC7 (System Operations) controls that require documented safeguards against credential compromise and network‑level attacks.
  • Continuous evidence of DNS‑change monitoring, captive‑portal configuration reviews, and user‑awareness training provides audit‑ready proof that access‑control policies are enforced.

Who Is Affected – Hospitality providers (hotels, conference centers), their guests, and any organization whose staff rely on public Wi‑Fi to access Microsoft 365 services.

Recommended Actions

  • Map DNS‑change detection and captive‑portal hardening to SOC 2 CC6/CC7 controls; implement automated monitoring and retain logs as audit evidence.
  • Enforce MFA and conditional‑access policies for Microsoft 365 accounts accessed from untrusted networks.
  • Conduct targeted security‑awareness training on Wi‑Fi phishing and OAuth code‑phishing techniques.

Technical Notes – Attackers exploit DNS manipulation on captive‑portal equipment, then serve phishing pages that mimic Microsoft 365 login or OAuth device‑code flows. The Windows payloads (CornFlake, ChocoShell) are Go‑based RATs capable of keylogging, token theft, and data exfiltration; a variant also drops an Android APK via fake update prompts. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →