That hotel Wi-Fi sign-in page could be handing you malware - a new warning for travelers
Checking into a hotel and hopping straight onto its Wi-Fi is second nature. A campaign Microsoft detailed on July 31 is a good reason to slow down. Its researchers found a Russian state-linked group - tracked as Storm-2945, part of the outfit better known as Midnight Blizzard - quietly tampering with hotel and conference Wi-Fi to go after the people who connect to it. They've named it CaptiveCrunch, and it's been running since early May across hospitality networks in several countries.
Here's how it works. When you join a public network you usually hit a "captive portal" - that sign-in or terms-of-service page that pops up first. On the networks these attackers control, that page is rigged: they meddle with the network's traffic to redirect you to convincing fakes. Some are counterfeit Microsoft sign-in pages that pocket your password the moment you type it; others are bogus "browser update" or "Windows update" boxes with realistic progress bars. Download what they offer and you get malware - a remote-access trojan called CornFlake that logs your keystrokes and lifts saved browser passwords, or ChocoShell, which steals the login tokens that keep you signed in. The one piece of good news: the infection isn't silent. It only works if you actually download and run the file.
So the defence is a habit worth building before your next trip. Treat any update prompt that appears right after you join Wi-Fi as suspect - real updates never arrive through a hotel network's sign-in page. Where you can, use your phone's hotspot instead of shared Wi-Fi, and be wary of any page that wants you to log into your Microsoft account just to get online. Updating your laptop before you leave home means you won't be tempted by a fake "you must update" box on the road.
That last point is where Tendvane fits: it gives you one trusted place to update Windows apps and drivers, pulled from Windows' own package manager, so the only update prompts worth acting on are the ones inside the app - never a pop-up on a network you don't control.