Threat Actors Hijack Public Wi-Fi Infrastructure

Travelers staying in hotels and attending events at conference centers are facing a heightened security risk. Cybersecurity experts at Microsoft have uncovered evidence that a Russian state-sponsored hacking group, widely recognized as APT29 or 'Midnight Blizzard,' is actively compromising captive portals—the gateway systems that manage Wi-Fi authentication for public networks.


By hijacking this networking equipment, attackers are able to intercept the connection process. When unsuspecting guests attempt to join the hotel Wi-Fi, they are often prompted to enter credentials or accept service terms. The attackers manipulate this redirection to deliver malicious content instead of the expected login page.


Deceptive Tactics and Phishing Schemes

According to the Microsoft investigation, victims on these compromised networks are frequently steered toward fraudulent landing pages designed to harvest sensitive information. The techniques employed include:

  • Fake Microsoft 365 Login Portals: Designed to trick users into revealing their primary business credentials.
  • Entra ID Phishing: Utilizing device code authentication flows to bypass standard login security.
  • Bogus Updates: Presenting deceptive browser or operating system update alerts that prompt the user to manually download and execute malicious files.

Malware Payloads: CornFlake and CocoShell

The research identified two primary malicious tools used by APT29 to compromise infected systems:

«CornFlake functions as a comprehensive information stealer, masquerading as a legitimate 'Cloud Sync Service.' It grants the attackers remote shell access, captures screenshots, records audio and video via peripheral devices, and exfiltrates files, clipboard data, and browser credentials.»


The second variant, CocoShell, is a specialized PowerShell-based tool that operates within the system memory. It is specifically engineered to siphon browser cookies, saved passwords, and authentication tokens related to Microsoft 365 and Azure AD, effectively giving the attackers persistent access to the victim's digital identity.


Background on APT29

The group behind these attacks, APT29, remains one of the most prominent state-sponsored hacking organizations in the world. With long-standing ties to the Russian Foreign Intelligence Service, the group has a history of high-profile cyber operations. Their targets have historically included western government officials, as well as major software and technology organizations.