Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: Win an ASUS TUF Gaming B850-PRO WiFi 7 and 360mm ARGB AIO

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials

Microsoft says Midnight Blizzard is using rogue hotel Wi-Fi networks and NTLM relay attacks to capture Windows hashes and access accounts.

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials
Comments
Tech Reporter
Published
1 minute & 30 seconds read time
TL;DR: Russian-linked group Midnight Blizzard (Cozy Bear) uses fake hotel Wi‑Fi "Evil Twin" networks and NTLM relay attacks to capture Windows authentication hashes and access accounts of traveling government, diplomatic, and defense personnel. Attack traffic is routed through chained compromised devices, complicating attribution. Use a VPN, confirm network names, or use a trusted mobile hotspot.
Voice: Hassam Nasir
0:00 / 2:32
Use left and right arrow keys to seek audio.

A Russian hacking group known as Midnight Blizzard, or Cozy Bear, has been running a campaign that specifically targets hotel Wi-Fi networks to get into the devices of government officials, diplomats, and defense industry employees while they travel. Microsoft's threat intelligence team published details of the campaign this week, and the technique being used is one worth understanding if you travel for work.

The attack is called an Evil Twin, and the basic idea is that the hackers set up a rogue Wi-Fi network that mimics a legitimate hotel network. When a target connects, the attacker intercepts traffic and can steal credentials through a technique called NTLM relay, which captures Windows authentication hashes and uses them to access the victim's accounts and internal systems without ever needing the actual password. The attack is entirely passive from the victim's perspective. You connect to what looks like the hotel Wi-Fi, and that is it.

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials 1

What makes Midnight Blizzard specifically dangerous is the infrastructure behind the operation. Microsoft found evidence that the group was chaining together compromised devices, including home routers and IoT hardware from previous campaigns, to route its attacks through. This makes the traffic harder to trace and the attackers harder to attribute. The group has been active since at least 2018 and is widely believed to be linked to Russia's SVR foreign intelligence service.

The targets are consistent with Russian intelligence priorities: NATO member government officials, people working in defense contracting, and anyone with access to sensitive foreign policy information. Hotels are attractive because targets are away from their corporate networks, often more relaxed about security, and connecting to infrastructure they have no control over.

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials 2

Frequently Asked Questions

TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.

Question #1

How does an Evil Twin Wi‑Fi setup by Midnight Blizzard capture Windows NTLM hashes from a connected device?

Question #2

Which types of devices or systems did Microsoft find were being chained to route Midnight Blizzard’s hotel Wi‑Fi attacks?

Question #3

How effective is using a VPN on hotel Wi‑Fi against NTLM relay attacks described in the article?

Question #4

Can an NTLM relay attack let attackers access corporate or internal systems without a password, and how does that work?

Have a question not listed here? Ask below and TweakBot will answer it.

The practical advice has not changed much in years but is worth repeating. A VPN on public Wi-Fi is the single most effective mitigation. Verifying the exact network name with hotel staff before connecting matters more than people realize. And for anything sensitive, a mobile hotspot from a carrier you trust is a better option than hotel Wi-Fi regardless of how legitimate it looks.

Photo of the Microsoft Surface Laptop (2025)

Best Deals: Microsoft Surface Laptop (2025)

Prices last scanned 1 hour and 47 minutes ago

* Prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commission from any Newegg or PCCG sales.

News Source:microsoft.com

Comments

Tech Reporter

Email IconX IconLinkedIn Icon

Hassam is a veteran tech journalist and editor with over eight years of experience embedded in the consumer electronics industry. His obsession with hardware began with childhood experiments involving semiconductors, a curiosity that evolved into a career dedicated to deconstructing the complex silicon that powers our world. From benchmarking PC internals to stress-testing flagship CPUs and GPUs, Hassam specializes in translating high-level engineering into deep, unbiased insights for the enthusiast community.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News
Newsletter Subscription