Russian spies turn public Wi-Fi into malware delivery systems
Keyloggers, audio-visual surveillance, and token theft on CaptivePortal's agenda as hospitality sector put on alert..

Keyloggers, audio-visual surveillance, and token theft on CaptivePortal's agenda as hospitality sector put on alert.
The short version
- Microsoft is still trying to determine how the hackers initially compromise captive-portal networks.
- The broader AI-assisted operation dates to February 2026, with traffic manipulation observed since early May.
- After gaining control of the network layer, Storm-2945 manipulates DNS and HTTP traffic to reroute users through attacker-controlled infrastructure, Microsoft said.
What happened
The crew also abuses operating systems' connectivity checks to trigger malicious prompts and redirects. This gives the attackers an adversary-in-the-middle (AitM) position.
Why it matters
Such prompts adopt ClickFix-style methods , which in some cases try to convince public Wi-Fi users to install malware under the guise of OS updates, driver repairs, and web verification failures.
Summary by Nerd News Network. Read the full article at The Register — Networks via the links above and below.
