Midnight Blizzard Targets Travelers via Captive Portals
Overview
A Russian cyber group known as Storm-2945 has been targeting travelers by hijacking hotel captive portals. These portals, which are the web pages that guests see when trying to access the internet in hotels, have been manipulated to deliver fake updates. When users attempt to connect to the Wi-Fi, they are prompted to download these updates, which actually steal their session tokens. This attack affects anyone using hotel Wi-Fi, putting personal information at risk. Users need to be cautious when connecting to public networks and avoid downloading software from unverified sources, as this method can lead to credential theft and unauthorized access to accounts.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Hotel captive portals, user session tokens
- Action Required: Avoid downloading software from unverified sources when connected to public Wi-Fi networks.
- Timeline: Newly disclosed
Original Article Summary
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
Impact
Hotel captive portals, user session tokens
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Avoid downloading software from unverified sources when connected to public Wi-Fi networks.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.