Newsletter IconGoogle IconFacebook IconX IconThreads IconInstagram IconYouTube Icon
Giveaway: GAMDIAS ATLAS P1 Case, HELIOS 750W PSU, and BOREAS Digital CPU Cooler

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials

Microsoft says Midnight Blizzard is using rogue hotel Wi-Fi networks and NTLM relay attacks to capture Windows hashes and access accounts.

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials
Facebook IconX IconReddit Icon
Comments
Senior Tech Reporter
Published
1 minute & 30 seconds read time
TL;DR: Russian-linked group Midnight Blizzard (Cozy Bear) uses fake hotel Wi‑Fi "Evil Twin" networks and NTLM relay attacks to capture Windows authentication hashes and access accounts of traveling government, diplomatic, and defense personnel. Attack traffic is routed through chained compromised devices, complicating attribution. Use a VPN, confirm network names, or use a trusted mobile hotspot.
Voice: Hassam Nasir
0:00 / 2:32
Use left and right arrow keys to seek audio.

A Russian hacking group known as Midnight Blizzard, or Cozy Bear, has been running a campaign that specifically targets hotel Wi-Fi networks to get into the devices of government officials, diplomats, and defense industry employees while they travel. Microsoft's threat intelligence team published details of the campaign this week, and the technique being used is one worth understanding if you travel for work.

The attack is called an Evil Twin, and the basic idea is that the hackers set up a rogue Wi-Fi network that mimics a legitimate hotel network. When a target connects, the attacker intercepts traffic and can steal credentials through a technique called NTLM relay, which captures Windows authentication hashes and uses them to access the victim's accounts and internal systems without ever needing the actual password. The attack is entirely passive from the victim's perspective. You connect to what looks like the hotel Wi-Fi, and that is it.

Popular Now: Only 19,000 people have successfully reserved Valve's Steam Frame, with many still on the waitlist
Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials 1

What makes Midnight Blizzard specifically dangerous is the infrastructure behind the operation. Microsoft found evidence that the group was chaining together compromised devices, including home routers and IoT hardware from previous campaigns, to route its attacks through. This makes the traffic harder to trace and the attackers harder to attribute. The group has been active since at least 2018 and is widely believed to be linked to Russia's SVR foreign intelligence service.

The targets are consistent with Russian intelligence priorities: NATO member government officials, people working in defense contracting, and anyone with access to sensitive foreign policy information. Hotels are attractive because targets are away from their corporate networks, often more relaxed about security, and connecting to infrastructure they have no control over.

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials 2

Frequently Asked Questions

Open a question for an answer from TweakTown's coverage of this news, or ask your own below.

Question #1

How does an Evil Twin Wi‑Fi setup by Midnight Blizzard capture Windows NTLM hashes from a connected device?

The attackers set up a rogue Wi-Fi network that mimics the legitimate hotel network and wait for targets to connect. Once a victim connects, the attacker intercepts traffic and performs an NTLM relay attack that captures the Windows authentication hashes. The stolen NTLM hashes are then used to access the victim's accounts and internal systems without needing the actual password, and the whole process appears passive to the victim.
Question #2

Which types of devices or systems did Microsoft find were being chained to route Midnight Blizzard’s hotel Wi‑Fi attacks?

Microsoft found the group was chaining together compromised devices, including home routers and IoT hardware, to route its attacks.
Question #3

How effective is using a VPN on hotel Wi‑Fi against NTLM relay attacks described in the article?

According to the article, using a VPN on public Wi-Fi is the single most effective mitigation against the described Evil Twin and NTLM relay attacks. The article recommends a VPN as the best protection, alongside verifying the exact network name with hotel staff and using a trusted mobile hotspot for anything sensitive.
Question #4

Can an NTLM relay attack let attackers access corporate or internal systems without a password, and how does that work?

Yes. According to the article, attackers set up an Evil Twin rogue Wi-Fi that mimics a hotel network and, when a target connects, use NTLM relay to capture Windows authentication hashes. The attackers then relay those captured hashes to access the victim's accounts and internal systems without ever needing the actual password, and the attack appears passive to the victim.

Have a question that isn't listed here? Ask below, and TweakBot will answer it.

The practical advice has not changed much in years but is worth repeating. A VPN on public Wi-Fi is the single most effective mitigation. Verifying the exact network name with hotel staff before connecting matters more than people realize. And for anything sensitive, a mobile hotspot from a carrier you trust is a better option than hotel Wi-Fi regardless of how legitimate it looks.

Photo of the Microsoft Surface Laptop (2025)

Best Deals: Microsoft Surface Laptop (2025)

Prices last scanned 6 hours and 18 minutes ago

* Prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commissions from Newegg and PCCG sales.

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

News Source:microsoft.com

Comments

About the author

Senior Tech Reporter

Hassam is a veteran tech journalist and editor with over eight years of experience embedded in the consumer electronics industry. His obsession with hardware began with childhood experiments involving semiconductors, a curiosity that evolved into a career dedicated to deconstructing the complex silicon that powers our world. From benchmarking PC internals to stress-testing flagship CPUs and GPUs, Hassam specializes in translating high-level engineering into deep, unbiased insights for the enthusiast community.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Follow TweakTown on GoogleAdd TweakTown as a preferred source on Google
Newsletter Subscription