language
Detectat automat

Am preselectat Română și Romanian Leu (lei) pentru tine.

Autentificare
softwarebay.de
softwarebay.de
Microsoft Warns of Phishing Attacks via Public Wi-Fi
News Cybersecurity Microsoft Warns of Phishing Attacks via Public Wi-...
Cybersecurity

Microsoft Warns of Phishing Attacks via Public Wi-Fi

Microsoft Warns of Phishing Attacks via Public Wi-Fi

Microsoft has issued a warning urging caution when using public Wi-Fi networks. The company's security department has identified a group of Russian hackers known as Storm-2945, who redirect users through manipulated DNS requests to phishing sites that mimic Microsoft online services. These attacks aim to steal credentials for Microsoft accounts. The warning follows a report from security researchers that was initially published in July 2026. Microsoft has now updated the information, noting that the hackers' activities have been observed since May 2026.

The attackers are exploiting public Wi-Fi networks, particularly in hotels and airports, to carry out their attacks. On the phishing sites to which users are redirected, the attackers attempt to capture device and OAuth codes. These codes enable the hackers to take over the respective Microsoft accounts. Additionally, it has been reported that the attackers install malware on users' devices, which functions as a Trojan. The malware has the capability to log keystrokes, activate microphones, and spy through the devices' cameras.

Furthermore, it can forward files and passwords to the attackers and establish remote access to the infected devices. These attacks are particularly dangerous as they are facilitated by compromised network equipment in public Wi-Fi networks. Microsoft is currently investigating how the hackers were able to infiltrate the network devices. A potential attack vector could be the use of captive portals, where users must agree to terms of use. Microsoft has noted that there are striking similarities among the devices and management systems used in several affected networks.

Microsoft's security researchers have found indications that the hackers' activities may not be limited to individual locations. Instead, it could involve access to shared services within the captive portal ecosystem. Microsoft refers to this wave of attacks as “CaptiveCrunch” and attributes it to the hacker group Storm-2945, which is linked to the Russian foreign intelligence service SVR. To protect against these attacks, Microsoft recommends always using a VPN on public Wi-Fi. Users should, if possible, avoid using public Wi-Fi altogether and instead utilize their mobile networks.

Microsoft explicitly warns: “When traveling, users should consider Wi-Fi networks in hotels, conferences, airports, and other guest networks as untrustworthy.” Additionally, it is advised to use personal mobile routers to enhance security. Microsoft has urged users to remain vigilant and report suspicious activities. The security situation remains tense, and Microsoft continues to work on clarifying the incidents. The warning from Microsoft comes at a time when cyberattacks are increasing globally. According to the Cybersecurity Report 2026, there was a 45% increase in phishing attacks in the first half of 2026 compared to the previous year. Microsoft plans to strengthen security measures in its services by the end of 2026.

Tags: Microsoft Cybersecurity Phishing Wi-Fi Hackers

💬 Comentarii (0)

Scrie un comentariu

info Va fi publicat dupa moderare
chat_bubble_outline

Inca nu exista comentarii. Fii primul!

Live support available
Veni Aria E.
Veni Aria E.
check_circle Brasov
Hello! I am Veni Aria. Do you have questions about our products or need help?
chat_bubble