Travelers targeted when logging into hotel Wi‑Fi networks
What Happened — A Russian‑linked threat group, dubbed CaptiveCrunch, is compromising hotel, conference‑center and other hospitality Wi‑Fi captive portals. By hijacking DNS and HTTP traffic, the attackers redirect users to phishing pages that harvest Microsoft 365 SSO tokens, OAuth credentials and device codes, and they also deliver the CornFlake RAT and the file‑less ChocoShell infostealer.
Why It Matters for Compliance & Audit Readiness
- Credential‑theft via public‑Wi‑Fi is a classic “access‑control” failure that SOC 2 CC 6.2 (Logical Access) and CC 7.1 (Security Awareness) are designed to prevent and evidence.
- Continuous monitoring of authentication logs, MFA enforcement and documented user‑training programs provide the audit‑ready proof that the organization mitigates this vector.
- Verisq’s SOC 2 Access Controls capability supplies automated evidence collection (login anomalies, MFA usage, VPN adoption) that can be attached to an audit package.
Who Is Affected – Enterprises that allow employees to travel and use public Wi‑Fi, especially in finance, SaaS, and professional services sectors.
Recommended Actions –
- Enforce MFA for all cloud services and require conditional access policies that block logins from unsecured networks.
- Mandate VPN use with a kill‑switch for any public‑Wi‑Fi session; log VPN start/stop events for audit evidence.
- Update security‑awareness training to include captive‑portal phishing and safe‑travel guidelines.
- Deploy network‑traffic monitoring (DNS‑filtering, TLS inspection) on corporate devices to detect MITM attempts.
Source: Malwarebytes Labs
Technical Notes – The campaign manipulates DNS responses and injects malicious HTTP redirects. Malware families observed: CornFlake (RAT) and ChocoShell (file‑less PowerShell infostealer). Attack vectors: phishing pages, fake Windows‑update dialogs, and MITM proxying. Source: same as above