Does Using Public Wi-Fi Automatically Allow Hackers To Record Your Mobile Screen and Audio?
Microsoft has uncovered a global cyber threat targeting travelers on public Wi-Fi networks at hotels and conference centres. According to a Microsoft post, the CaptiveCrunch campaign uses traffic manipulation and fake update prompts to distribute malware, steal browser credentials, and compromise corporate accounts worldwide.
Microsoft has issued a security alert regarding a sophisticated global cyber espionage campaign targeting travelers through compromised hospitality network connections. The malicious activity, tracked under the name CaptiveCrunch, manipulates internet traffic on public networks to distribute malware and harvest sensitive corporate credentials from unsuspecting users.
Security researchers attribute the ongoing operation to Storm-2945, an operational sub-cluster linked to the Russia-based threat group known as Midnight Blizzard. As per a post by Microsoft, the campaign has successfully targeted public Wi-Fi infrastructure at hotels, conference centres, and shared travel hubs across multiple countries since early May. World Quantum Day 2026: Focus Shifts to AI and Cybersecurity As India Launches Indigenous Testing Facility.
Tactics Used in CaptiveCrunch Attacks
The operation typically begins when travelers connect to public wireless networks serviced by captive login portals. Attackers manipulate network traffic to redirect users toward malicious infrastructure, where fake prompts masquerade as mandatory software updates, browser patches, or operating system upgrades.
Once executed on a victim's device, the malicious payloads deploy remote access tools designed to monitor activity, capture keystrokes, and extract stored browser credentials. In addition to malware deployment, the threat actors utilize deceptive phishing pages to hijack authentication workflows, specifically targeting device code logins to access corporate cloud accounts.
Defending Against Hospitality Network Risks
Cybersecurity specialists recommend that frequent travelers exercise extreme caution when utilizing public Wi-Fi networks in hotels and airports. Experts advise prioritizing secure mobile hotspots or private cellular connections over unverified guest networks whenever possible. Framework Computer Data Breach: US-Based PC Brand Warns Users After Metabase Zero-Day Exploit Exposes Personal Details.
Organizations are also urged to strengthen their identity management practices by disabling unnecessary device code authentication flows, implementing robust multi-factor authentication, and educating employees to recognize deceptive system prompts encountered while traveling.
(The above story first appeared on LatestLY on Aug 10, 2026 02:04 PM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).