Russian APT Group Linked to Public Wi-Fi Hacking, Cybersecurity Threat
Russian state-sponsored cyber actors have been linked to a campaign targeting public Wi-Fi gateway systems, according to findings disclosed by Microsoft.
Microsoft’s Findings on DNS Manipulation
Russian state-sponsored cyber actors have been linked to a campaign targeting public Wi-Fi gateway systems, according to findings disclosed by Microsoft. The operation, identified through analysis of compromised small office/home office (SOHO) routers, involved manipulation of Domain Name System (DNS) configurations to reroute users to malicious infrastructure. This technique enabled adversaries to intercept Microsoft 365 credentials from employees in critical sectors including financial services, professional services, legal, healthcare, energy, and retail.
ReliaQuest Detection
ReliaQuest first detected the activity approximately one week prior, noting the use of adversary-in-the-middle (AitM) tactics to exploit unsecured Wi-Fi networks.
FrostArmada and APT28
The campaign exhibited similarities to FrostArmada, an espionage effort previously associated with APT28, a group tied to Russian intelligence. However, no definitive attribution was made in the initial report.
Microsoft’s Confirmation of Storm-2945
Microsoft later confirmed the involvement of Storm-2945, a subgroup of Midnight Blizzard (also known as APT29, Cozy Bear, and Yttrium). This actor is known for targeting government entities, diplomatic organizations, non-governmental organizations (NGOs), and IT service providers in the United States and Europe to support Russian geopolitical objectives.
Captive Portal Networks and CaptiveCrunch Campaign
Storm-2945 specifically leveraged captive portal networks, such as those found in hotels and hospitality venues, to manipulate DNS and HTTP traffic. Attackers deployed Golang-based Windows remote access trojans (RATs) disguised as browser updates through a campaign dubbed CaptiveCrunch. These implants enabled reconnaissance, credential theft, session token extraction, file and keystroke collection, audio/video surveillance, and remote command execution.
ClickFix Techniques and Microsoft’s Report
The threat group utilized ClickFix techniques to deceive users into installing malicious payloads. Microsoft reported widespread compromises of Wi-Fi networks at hospitality organizations and other entities relying on captive portal systems across multiple countries.
CornFlake RAT and ChocoShell Infostealer
Storm-2945 targeted Windows users with the CornFlake RAT and a PowerShell-based infostealer called ChocoShell, managing operations through a web-based command-and-control (C&C) panel named FruitStone.
Device Code Authentication Flows
Over the past two weeks, Microsoft observed CaptiveCrunch landing pages directing victims to device code authentication flows. Users were prompted to enter codes on Microsoft sign-in pages, effectively granting attackers access to their sessions. This method aligns with previously documented device code phishing campaigns by Midnight Blizzard since August 2024.
Evolving Tactics and Mitigation Strategies
The campaign underscores the evolving tactics of state-sponsored actors in exploiting trusted network environments. Microsoft emphasized the importance of monitoring DNS configurations and implementing multi-factor authentication (MFA) to mitigate risks associated with such attacks.
Conclusion
The findings add to a broader pattern of Russian cyber activities targeting critical infrastructure and organizational networks, as highlighted by recent law enforcement actions and international warnings.
