Microsoft has issued a warning about a Russian hacking group targeting travelers through compromised hotel Wi-Fi networks. The operation, which Microsoft calls CaptiveCrunch, is attributed to Midnight Blizzard, a group believed to be linked to Russian intelligence services.

The attack exploits hotel Wi-Fi infrastructure to intercept guests when they connect to the network. Hackers redirect users to fake login pages designed to steal usernames and passwords, and may attempt to install malware on travelers' devices. By compromising the router itself, attackers can redirect users to fraudulent sites and potentially access other devices connected to the network, such as phones and computers.

The UK's National Cyber Security Centre has warned about similar operations targeting commonly sold internet routers. According to the agency, these attacks follow a pattern where actors target a wide pool of victims before filtering for users of potential intelligence value. Experts note that edge devices like routers and security cameras often represent weak points in network security because they frequently lack updates and proper monitoring.

"Edge devices are quite often forgotten about, and they can become a weak point," said Alan Woodward, a professor at the University of Security at the University of Surrey. Once attackers access a router, they can redirect users to fake sites and establish themselves on networks to probe for vulnerabilities in connected devices.

The group behind the attacks is probably APT28, also known as Fancy Bear, which was almost certainly linked to Russian intelligence services. APT28 was responsible for cyber-attacks on the German parliament in 2015, when large amounts of data including confidential emails and schedules of German MPs were stolen.

The warning highlights growing concerns about the security of internet routers. The US Federal Communications Commission has recently banned the sale of all consumer-grade routers made outside the United States, stating that foreign-made routers pose unacceptable risks to national security. The agency noted that malicious actors have exploited security gaps in foreign-made routers to attack American households, disrupt networks, and facilitate espionage and intellectual property theft.

However, privacy experts caution that an outright ban may not fully address vulnerabilities in existing routers already in use. A more significant problem is that many internet routers currently in service are at the end of their operational lives and no longer receive security updates.

Microsoft recommends that travelers use virtual private networks when connecting to hotel Wi-Fi and avoid entering sensitive credentials on public networks. The company also suggests enabling multi-factor authentication and remaining cautious of unexpected login prompts. Organizations with employees who travel frequently should update their security policies to address the heightened risk of compromised hotel networks. For small businesses and individuals, experts recommend keeping routers updated and monitoring networks for unusual activity.