<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CaptiveCrunch]]></title><description><![CDATA[<blockquote>
<p dir="auto">Microsoft has warned that hotel, conference, and other hospitality Wi-Fi networks are being actively abused by a Russian group to target travelers worldwide. The campaign, dubbed “CaptiveCrunch” turns a routine Wi-Fi login moment into an opportunity to compromise corporate accounts and devices.</p>
<p dir="auto">From the user’s perspective, nothing looks out of the ordinary: they connect to hotel Wi-Fi, get the usual captive portal prompt, and perhaps see a familiar‑looking message about needing to update something before they can browse. However, behind the scenes, the allegedly state-linked group position themselves in the network path and manipulate DNS (Domain Name System) and HTTP traffic from captive‑portal Wi-Fi.</p>
<p dir="auto">From there, several things can happen:</p>
<p dir="auto">Logins are stolen: The user’s browser session is redirected to attacker‑controlled phishing pages, like fake Microsoft login prompts, where credentials, device codes, or OAuth tokens are harvested.</p>
<p dir="auto">Malware is downloaded: The user is presented with fake update or ClickFix dialogs that download malware. In these cases, usually a remote access trojan (RAT) plus an infostealer.</p>
<p dir="auto">A machine-in-the-middle attack (MitM) where traffic is quietly proxied through attacker infrastructure, putting the user in a position for further credential theft.</p>
</blockquote>
<p dir="auto"><a href="https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks</a></p>
]]></description><link>https://wtf.coffee-room.com/topic/3948/captivecrunch</link><generator>RSS for Node</generator><lastBuildDate>Mon, 10 Aug 2026 23:11:47 GMT</lastBuildDate><atom:link href="https://wtf.coffee-room.com/topic/3948.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 10 Aug 2026 18:59:38 GMT</pubDate><ttl>60</ttl></channel></rss>