[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fd8uCo5fnI3RfJw8FJTTGXXe7mOXptj1dfmCKUs8mcNs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"dbd025ba-f308-41b7-a452-a796dd00dc17","apt29-hijacks-hotel-wi-fi-to-deliver-fake-updates-and-steal-credentials","ebe4279a-385e-41f1-bffa-425d5f9e4d94","APT29 Hijacks Hotel Wi-Fi to Deliver Fake Updates and Steal Credentials","The CaptiveCrunch campaign exploits a fundamental trust gap: users on unfamiliar hotel networks are conditioned to accept captive portal prompts, making them susceptible to fake browser update lures. By abusing Microsoft's device code authentication flow, attackers can bypass MFA entirely, meaning even well-configured accounts are at risk once a user interacts with a malicious page. The delivered malware — CornFlake and ChocoShell — specifically targets Microsoft 365 and Azure AD tokens, giving attackers persistent, privileged cloud access long after the initial compromise. This attack matters because it targets high-value individuals (executives, diplomats, government personnel) in transient, low-trust network environments where vigilance is naturally reduced.","**Immediate actions:**\n- Train employees to never accept software update prompts while connected to public or hotel Wi-Fi networks.\n- Enforce conditional access policies that block Microsoft device code authentication flow from untrusted or non-compliant devices.\n- Require the use of a corporate VPN before accessing any Microsoft 365 or Azure AD resources on non-corporate networks.\n\n**Long-term improvements:**\n- Deploy phishing-resistant MFA (e.g., FIDO2\u002Fhardware keys) to eliminate vulnerability to device code authentication abuse.\n- Implement Zero Trust Network Access (ZTNA) so that network location (including hotel Wi-Fi) never implicitly grants trust to any resource.\n- Establish and enforce a policy requiring travelers to use mobile hotspots or always-on VPN instead of public Wi-Fi.\n\n**Detection measures:**\n- Monitor Azure AD sign-in logs for unusual device code authentication attempts or logins from unexpected geographies.\n- Alert on new OAuth token issuances from unmanaged or non-compliant devices accessing sensitive Microsoft 365 workloads.\n- Deploy endpoint detection capable of identifying Go-based RAT behavior and anomalous PowerShell execution patterns.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 9: Email and Web Browser Protections","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-207: Zero Trust Architecture","NIST AC-17: Remote Access","NIST AC-20: Use of External Systems","NIST IA-2(6): Phishing-Resistant MFA","NIST SI-3: Malicious Code Protection","NIST AU-12: Audit Record Generation","MITRE ATT&CK T1566: Phishing (User Execution - Malicious Link)","MITRE ATT&CK T1550.001: Use Alternate Authentication Material (Application Access Token)","MITRE ATT&CK T1528: Steal Application Access Token","GDPR Article 32: Security of Processing (for organizations subject to EU data protection law)","published","2026-08-01T08:20:34.606179+00:00","2026-08-01T08:20:34.539+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fhijacked-hotel-wi-fi-pushes-fake.html","hijacked-hotel-wi-fi-pushes-fake-updates-to-deliver-surveillance-malware-ef832f","Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":41,"name":42,"slug":43,"description":44,"color":45},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":47,"name":48,"slug":49,"description":50,"color":51},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[53,59],{"id":54,"date":55,"edition":56,"title":57,"audio_url":58},"bd004071-9bf5-45f0-8ec9-b8639fffa05f","2026-08-02","morning","ThreatNoir Weekend Brief — August 2","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-02\u002Fthreatnoir-morning-brief-2026-08-02.mp3",{"id":60,"date":61,"edition":62,"title":63,"audio_url":64},"f5e392e1-3964-441a-8ae0-c547ff9af5d7","2026-08-01","afternoon","ThreatNoir Weekend Brief — August 1","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-01\u002Fthreatnoir-afternoon-brief-2026-08-01.mp3"]