Microsoft Warns Hotel Wi-Fi Portals Are Under Active Attack
Public Wi-Fi has long been known to pose numerous security risks, which is why so many cybersecurity experts warn against using it without a VPN or other methods to protect the anonymity of your traffic and devices. What is new is the scope and infrastructure behind these CaptiveCrunch attacks, which are being run by Russian hacking group Storm-2945, which is a sub-cluster of the larger Midnight Blizzard group.

Midnight Blizzard is explicitly targeting travelers or other vulnerable users who connect to public hotspots.
Microsoft's investigation into how these networks are initially compromised is still ongoing, but patterns suggest the attackers have access to shared services within the captive portal ecosystem. The full capabilities of a CaptiveCrunch attack once malware is installed is comprehensive and includes keylogging, credential theft, audio/video surveillance, USB drive monitoring, and even remote command execution to PowerShell or Command Prompt.
To protect against CaptiveCrunch, Microsoft recommends users minimize trust in guest networks and using private connectivity (via personal mobile hotspot, etc.,) educating organization members on phishing prompts, employing multi-factor authentication (MFA,) and other common security tips. In its full blog post, Microsoft also lists a series of Microsoft Defender detections that are specific to CaptiveCrunch attacks and Indicators of Compromise (IoCs.) If you or your organization members frequently use public Wi-Fi for any reason, we highly recommend checking out those IoCs.
Image Credit: ProtoplasmaKid on WikiMedia Commons (CC 4.0 Share-alike License)