Hackers linked to Russia’s Foreign Intelligence Service intercepted hotel Wi-Fi worldwide to steal officials’ and executives’ data
AI Generated Image

Hackers linked to Russia’s Foreign Intelligence Service intercepted hotel Wi-Fi worldwide to steal officials’ and executives’ data

theins.press technology

Key Points:

  • Russian state-linked hackers, associated with the Storm-2945 and Midnight Blizzard groups, have been infiltrating hotel and conference Wi-Fi networks worldwide since early 2026 to steal data from corporate employees on business trips, according to Microsoft Threat Intelligence.
  • The attackers intercepted DNS and HTTP traffic, redirecting users through malicious infrastructure to deliver malware disguised as browser or operating system updates, and used fake error messages to trick victims into running harmful scripts.
  • Key tools in the campaign include the CornFlake remote-access Trojan, which records keystrokes and captures screenshots, and the ChocoShell infostealer, which targets saved passwords and tokens; infected devices were managed through a web panel called FruitStone, with AI aiding operations.
  • Midnight Blizzard, linked to Russia’s Foreign Intelligence Service (SVR), primarily targets governments, diplomatic missions, NGOs, and tech companies in the U.S. and Europe to gather intelligence supporting Russian foreign policy.
  • Microsoft recommends treating public Wi-Fi at hotels, conferences, and airports as unsafe, using mobile internet when possible, and avoiding software updates prompted by pop-ups or login pages; previous Russian hacking campaigns have also targeted U.S. defense employees and nuclear fusion researchers.

Trending Business

Trending Technology

Trending Health