A Russian hacking group known as Midnight Blizzard, or Cozy Bear, has been running a campaign that specifically targets hotel Wi-Fi networks to get into the devices of government officials, diplomats, and defense industry employees while they travel. Microsoft's threat intelligence team published details of the campaign this week, and the technique being used is one worth understanding if you travel for work.
The attack is called an Evil Twin, and the basic idea is that the hackers set up a rogue Wi-Fi network that mimics a legitimate hotel network. When a target connects, the attacker intercepts traffic and can steal credentials through a technique called NTLM relay, which captures Windows authentication hashes and uses them to access the victim's accounts and internal systems without ever needing the actual password. The attack is entirely passive from the victim's perspective. You connect to what looks like the hotel Wi-Fi, and that is it.

What makes Midnight Blizzard specifically dangerous is the infrastructure behind the operation. Microsoft found evidence that the group was chaining together compromised devices, including home routers and IoT hardware from previous campaigns, to route its attacks through. This makes the traffic harder to trace and the attackers harder to attribute. The group has been active since at least 2018 and is widely believed to be linked to Russia's SVR foreign intelligence service.
The targets are consistent with Russian intelligence priorities: NATO member government officials, people working in defense contracting, and anyone with access to sensitive foreign policy information. Hotels are attractive because targets are away from their corporate networks, often more relaxed about security, and connecting to infrastructure they have no control over.


Frequently Asked Questions
TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.
How does an Evil Twin Wi‑Fi setup by Midnight Blizzard capture Windows NTLM hashes from a connected device?
Which types of devices or systems did Microsoft find were being chained to route Midnight Blizzard’s hotel Wi‑Fi attacks?
How effective is using a VPN on hotel Wi‑Fi against NTLM relay attacks described in the article?
Can an NTLM relay attack let attackers access corporate or internal systems without a password, and how does that work?
Have a question not listed here? Ask below and TweakBot will answer it.
The practical advice has not changed much in years but is worth repeating. A VPN on public Wi-Fi is the single most effective mitigation. Verifying the exact network name with hotel staff before connecting matters more than people realize. And for anything sensitive, a mobile hotspot from a carrier you trust is a better option than hotel Wi-Fi regardless of how legitimate it looks.






