Back to all lessons
Awareness Lessons
2 months ago

APT29 Hijacks Hotel Wi-Fi to Deliver Fake Updates and Steal Credentials

The CaptiveCrunch campaign exploits a fundamental trust gap: users on unfamiliar hotel networks are conditioned to accept captive portal prompts, making them susceptible to fake browser update lures. By abusing Microsoft's device code authentication flow, attackers can bypass MFA entirely, meaning even well-configured accounts are at risk once a user interacts with a malicious page. The delivered malware — CornFlake and ChocoShell — specifically targets Microsoft 365 and Azure AD tokens, giving attackers persistent, privileged cloud access long after the initial compromise. This attack matters because it targets high-value individuals (executives, diplomats, government personnel) in transient, low-trust network environments where vigilance is naturally reduced.

Tactical Insight

Immediate actions

  • Train employees to never accept software update prompts while connected to public or hotel Wi-Fi networks.
  • Enforce conditional access policies that block Microsoft device code authentication flow from untrusted or non-compliant devices.
  • Require the use of a corporate VPN before accessing any Microsoft 365 or Azure AD resources on non-corporate networks.

Long-term improvements

  • Deploy phishing-resistant MFA (e.g., FIDO2/hardware keys) to eliminate vulnerability to device code authentication abuse.
  • Implement Zero Trust Network Access (ZTNA) so that network location (including hotel Wi-Fi) never implicitly grants trust to any resource.
  • Establish and enforce a policy requiring travelers to use mobile hotspots or always-on VPN instead of public Wi-Fi.

Detection measures

  • Monitor Azure AD sign-in logs for unusual device code authentication attempts or logins from unexpected geographies.
  • Alert on new OAuth token issuances from unmanaged or non-compliant devices accessing sensitive Microsoft 365 workloads.
  • Deploy endpoint detection capable of identifying Go-based RAT behavior and anomalous PowerShell execution patterns.