You’ve likely heard the warnings that public wifi can’t always be trusted, and now Microsoft is giving you a good reason to avoid them. A new hacking campaign, known as CaptiveCrunch, is targeting wireless networks at hotels, conference centers, airports, and other hospitality venues in an attempt to steal credentials and compromise devices.
Hackers are targeting hospitality wifi networks
The warning comes from Microsoft Threat Intelligence, a group of security experts and researchers who found that Russian threat actors are using the captive portal prompts that appear when users connect to wifi to phish sensitive information and spread malware. Users are accustomed to seeing these pop-ups when logging onto public networks, so they’re less likely to be suspicious.
As Malwarebytes Labs describes, hackers are able to manipulate DNS and HTTP traffic from these portals, which allows them to send users to phishing sites (and harvest login credentials and device codes), push malware via fake update and ClickFix prompts, and run machine-in-the-middle attacks to intercept and redirect traffic. Users may see a number of fake dialog boxes when connecting to hotel or airport wifi, such as a Windows Update or Windows Security window or a prompt to download a PDF viewer or disk optimization utility.
How to keep your devices safe from public wifi attacks
Microsoft researchers are urging travelers to assume that public and guest wireless networks at hotels, conference centers, and airports are untrustworthy. Whenever possible, users should rely on private connections, such as mobile hotspots and cellular data, instead of logging onto public wifi. If you’re on a work device specifically, you should have an enterprise-managed travel router or hotspot that provides an encrypted connection to your company’s infrastructure.
If you must use hotel or airport wifi, Malwarebytes Labs recommends using a VPN with a killswitch, which blocks internet traffic if your connection drops unexpectedly. Inspect login pop-ups carefully, and be wary of portal pages that ask for information beyond a room number or last name in order to connect. Use an email alias if you need to provide an address.
Never download software or browser updates, certificates, tools, or utilities through captive portals, pop-up messages, or web prompts, as these may introduce malware to your device. If you are unsure whether an update is required, go directly to the service or your system settings. (You should never be required to download anything to connect to wifi.) If you’re prompted to copy code or run commands on your device, exit immediately, as this is a sign of a ClickFix attack. Anything urgent, such as a countdown timer, is also a red flag.
Finally, ensure your devices, apps, and software are up to date before you travel to patch security flaws and minimize the likelihood that you’ll need to download anything while you’re on the road.