Microsoft Threat Intelligence has issued a global security advisory regarding a sophisticated cyberattack campaign targeting users through compromised public Wi-Fi networks. Security researchers discovered that state-sponsored hackers are hijacking captive portals in hotels, airports, and conference centers to serve fake Windows updates that secretly infect devices with surveillance malware.
The operation, tracked by Microsoft under the name CaptiveCrunch, uses manipulated network traffic to trick users into executing malicious code disguised as routine system maintenance or security patches. Organizations and individual travelers are being advised to exercise extreme caution when connecting to public networks and to avoid downloading any software prompts displayed during Wi-Fi authentication.
Microsoft Fake Windows Update Warning and Attack Summary
According to findings published by Microsoft's security team, the ongoing campaign primarily targets business travelers and corporate employees accessing public networks. When a user attempts to connect to a hotel or event Wi-Fi network, the compromised captive portal redirects web traffic toward attacker-controlled servers. Instead of the standard login page, victims encounter convincing dialog boxes prompting them to install mandatory software updates, security patches, or browser fixes before accessing the internet.
Once a victim agrees to the installation, the system downloads advanced remote access trojans (RATs) and information stealers. Security researchers noted that these malicious binaries, including malware strains identified as CornFlake and ChocoShell, give attackers sweeping control over affected devices. Key capabilities of the payloads include logging keystrokes, recording audio and video through host peripherals, harvesting saved browser passwords, and stealing single sign-on tokens used for corporate Microsoft 365 accounts.
Microsoft Uncovers Captive Portal Cyberattack Campaign
The technical mechanics behind the CaptiveCrunch campaign involve compromise at the network infrastructure level. Threat actors exploit vulnerabilities within administrative management systems controlling hotel and public hotspot gateways. By acquiring control of the local gateway, attackers act as the primary Domain Name System (DNS) resolver for all connected guests.
When a laptop or mobile device performs an automatic network status check, the hijacked DNS resolver intercepts the query and alters the destination IP address. Instead of contacting legitimate update servers, the victim's web browser is routed to a malicious landing page hosted on external infrastructure.
How Attackers Use Fake Windows Updates to Deliver Malware
To maximize success rates, the threat group behind the campaign relies heavily on visual deception and social engineering techniques. The fake update screens closely replicate official Microsoft Windows 11 interface elements, complete with standard branding, progress bars, and corporate typography.
In several cases, landing pages instruct users to execute specific terminal commands to resolve fictitious network errors, a technique commonly referred to as the ClickFix method. By tricking users into manually running PowerShell commands or executable installers, the attackers bypass typical browser download protections. Furthermore, Microsoft noted that the campaign uses artificial intelligence tools to craft localized content and dynamic script variations, making detection by traditional antivirus scanners more difficult.
Scope and Targets of the Threat Group
Microsoft Threat Intelligence attributes the activity to a threat group tracked as Storm-2945, an operational sub-unit of the broader Midnight Blizzard state-sponsored threat group. Also known in the cybersecurity industry as APT29 or Cozy Bear, Midnight Blizzard is associated with Russia's Foreign Intelligence Service (SVR) and has a long history of high-profile cyber espionage operations.
The geographic reach of the campaign spans multiple countries, with confirmed incidents across North America, Europe, and Asia. Rather than launching opportunistic attacks against random consumers, the threat group specifically targets high-value individuals, corporate executives, government contractors, and diplomats who frequently rely on travel infrastructure.
Risks to Public Wi-Fi and Corporate Devices
The primary danger of this attack vector stems from its ability to bypass standard corporate perimeter defenses. When employees connect personal or company-issued laptops to hijacked guest networks, the initial compromise occurs outside the protection of corporate firewalls.
Because the malware captures authentication tokens and device codes, threat actors can maintain persistent access to enterprise cloud environments long after the user disconnects from the malicious Wi-Fi network. Stealing OAuth tokens allows attackers to bypass multi-factor authentication (MFA) prompts, granting direct entry into cloud repositories, proprietary emails, and internal communication platforms.
How Windows 11 Users Can Protect Their Systems
In light of these findings, security experts emphasize that users must adopt strict network hygiene protocols when traveling. Microsoft strongly advises against downloading any software updates, drivers, or security patches while connected to public or shared Wi-Fi portals. Legitimate operating system updates for Windows 11 are delivered directly through the native Windows Update menu in System Settings and never require manual execution via web browser pop-ups.
To mitigate exposure to captive portal manipulation, travelers should consider the following preventative measures:
- Use Cellular Hotspots: Connect corporate devices to personal cellular hotspots rather than untrusted hotel or airport networks whenever possible.
- Enable Virtual Private Networks (VPNs): Deploy an always-on, full-tunnel corporate VPN before opening web browsers on public networks, ensuring DNS requests are handled by secure corporate resolvers.
- Ignore Connectivity Update Prompts: Disregard any web page that claims an operating system update or browser patch is required to access internet service.
- Verify Windows Update Settings: Only perform system updates through the official Settings app (Settings > Windows Update) on Windows 11.
- Report Suspicious Portal Activity: Inform venue administrators and IT departments if a Wi-Fi portal requests unusual permissions or command execution.
Cybersecurity analysts warn that public Wi-Fi infrastructure will remain a high-value target for state-sponsored threat groups. As remote work and international travel continue to feature prominently in business operations, organization-wide policy updates and user awareness training remain critical components of defense against modern network redirection attacks.