Microsoft Flags a New Fake Wi-Fi Attack Campaign

Microsoft issued a warning on July 31 about a hacking group called Storm-2945, which the company identifies as a subgroup of Midnight Blizzard, a Russian-linked threat actor with a long history of state-aligned cyber operations. According to Microsoft, Storm-2945 is currently running an attack campaign that uses fake Wi-Fi login pages to target business travelers around the world.

While Microsoft's disclosure is still developing, the core detail is clear: attackers are exploiting the moment when travelers connect to public or hotel Wi-Fi networks, using deceptive login portals to compromise devices or steal credentials. This is not the first time Microsoft has attributed an intrusion to a Russian-linked group; the company also traced the ransomware attack on Thialf ice stadium to a separate threat group, underscoring how frequently Microsoft's threat intelligence team is now naming and tracking these actors publicly.

How a Fake Wi-Fi Login Attack Typically Works

Fake Wi-Fi login pages, sometimes called "evil twin" attacks or malicious captive portals, rely on a simple trick: they mimic the legitimate sign-in screen a traveler expects to see at an airport lounge, hotel, or conference venue. Instead of connecting to the real network, the victim's device joins a network controlled by the attacker, or is redirected through a spoofed portal designed to look identical to the genuine one.

From there, the attacker can harvest login credentials entered on the fake page, intercept unencrypted traffic, or attempt to push malicious software onto the connected device. Because business travelers often need to get online quickly to check email or join a call, these fake portals are designed to blend in and avoid raising suspicion. The tactic doesn't require sophisticated malware or a software vulnerability; it exploits trust in a familiar, everyday process.

This is part of why threat groups linked to state-sponsored operations, like the one behind Midnight Blizzard, continue to invest in this approach. It's low-cost, scalable, and effective against a population, business travelers, that frequently moves between untrusted networks and has valuable access to corporate systems, internal communications, or sensitive projects.

Why Business Travelers Are a Prime Target

Business travelers are attractive targets for several reasons. They frequently connect to networks they don't control and can't verify, they're often juggling multiple devices and accounts, and they may be under time pressure that makes them less likely to scrutinize a login page closely. For a Russian-linked group focused on espionage or intelligence gathering, compromising a traveling executive, diplomat, or researcher can provide a foothold into an organization's broader network, even if the initial device compromised isn't the ultimate target.

This campaign also reflects a broader trend: threat actors increasingly favor initial access methods that sidestep traditional network defenses entirely. Rather than exploiting a flaw in enterprise software or a VPN client, as seen in cases like the IKE vulnerability affecting Windows VPN services, attacks like this one target the human decision to click "connect" on an unfamiliar network. That makes awareness and basic operational hygiene just as important as technical patching.

What This Means For You

If you travel for work, even occasionally, this warning is a reminder that public Wi-Fi networks, especially in airports, hotels, and conference centers, should be treated as inherently untrusted. You don't need to be a high-profile executive to be swept up in a campaign like this; attackers casting a wide net at a venue may compromise anyone who connects, then sort out who's valuable afterward.

The good news is that the defenses against this kind of attack are straightforward and don't require specialized security tools. Verifying network names directly with venue staff, avoiding networks that ask for unusual personal information during login, and using a reputable VPN to encrypt your traffic on any public network are all practical steps that meaningfully reduce risk. Organizations that regularly send employees on business travel should also consider reinforcing basic Wi-Fi safety guidance as part of routine security training, since this kind of social engineering doesn't rely on outdated software or unpatched systems.

Actionable Takeaways

Before your next business trip, confirm official Wi-Fi network names with hotel or event staff rather than trusting whatever appears in your device's Wi-Fi list. Avoid entering sensitive credentials on a captive portal page that looks even slightly unfamiliar, and consider using a VPN by default whenever you connect to a network you don't control. If your organization has a travel security policy, review it before you go, and report anything suspicious to your IT or security team promptly. Microsoft's warning about Storm-2945 is a useful reminder that even a routine fake Wi-Fi attack can be the opening move in a much larger intrusion, and a few minutes of caution at the login screen can prevent it.