{"id":242143,"date":"2026-08-04T01:18:22","date_gmt":"2026-08-04T06:18:22","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts"},"modified":"2026-08-04T01:18:22","modified_gmt":"2026-08-04T06:18:22","slug":"hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts","title":{"rendered":"Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts.jpg\"><\/a><\/p>\n<p>Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.<\/p>\n<p>The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts\/\" rel=\"nofollow noopener\" target=\"_blank\">changed DNS settings<\/a> on Wi-Fi devices to steal Microsoft 365 accounts.<\/p>\n<p>Besides attributing the campaign to Russian hackers tracked as Storm-2945 \u2014 a sub-cluster of Midnight Blizzard, <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/07\/31\/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft identified<\/a> two malware families called CornFlake and ChocoShell with capabilities for persistent access, credential theft, surveillance, and data exfiltration.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker changed DNS settings on Wi-Fi devices to steal Microsoft 365 accounts. Besides attributing the campaign to Russian [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,418,1511],"tags":[],"class_list":["post-242143","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-internet","category-surveillance"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=242143"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242143\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=242143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=242143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=242143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}