Hotel Wi‑Fi Networks Compromised by Custom Malware, Leading to Microsoft 365 Credential Theft
What Happened – A global campaign dubbed CaptiveCrunch—attributed to the Russian APT29 group—has been hijacking hospitality Wi‑Fi infrastructure. Attackers modify DNS and HTTP traffic on captive‑portal devices, redirecting users to phishing pages that harvest Microsoft 365 credentials or deliver custom Windows malware families (CornFlake, ChocoShell).
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC6 (Logical Access) and CC7 (System Operations) controls that require documented safeguards against credential compromise and network‑level attacks.
- Continuous evidence of DNS‑change monitoring, captive‑portal configuration reviews, and user‑awareness training provides audit‑ready proof that access‑control policies are enforced.
Who Is Affected – Hospitality providers (hotels, conference centers), their guests, and any organization whose staff rely on public Wi‑Fi to access Microsoft 365 services.
Recommended Actions
- Map DNS‑change detection and captive‑portal hardening to SOC 2 CC6/CC7 controls; implement automated monitoring and retain logs as audit evidence.
- Enforce MFA and conditional‑access policies for Microsoft 365 accounts accessed from untrusted networks.
- Conduct targeted security‑awareness training on Wi‑Fi phishing and OAuth code‑phishing techniques.
Technical Notes – Attackers exploit DNS manipulation on captive‑portal equipment, then serve phishing pages that mimic Microsoft 365 login or OAuth device‑code flows. The Windows payloads (CornFlake, ChocoShell) are Go‑based RATs capable of keylogging, token theft, and data exfiltration; a variant also drops an Android APK via fake update prompts. Source: BleepingComputer