A hacker group linked to Russia's Foreign Intelligence Service (SVR) is reported to have carried out a large-scale cyberattack on Wi-Fi networks in hotels and other public places worldwide.
Modern.az reports that Microsoft has released information about this.
According to the company's statement, the attacks targeted Wi-Fi access systems called captive portals used in hotels, conference centers, and other public places. These are authentication pages that users encounter when connecting to a public wireless network.
Microsoft speculates that the hackers may have gained access to common services used by several Wi-Fi operators simultaneously. The company noted that if this scenario is confirmed, one successful attack could lead to the compromise of numerous hotel and public Wi-Fi networks.
According to the information, during the attack, users were unknowingly redirected to phishing infrastructure controlled by the hackers. They were then presented with malicious software under the guise of a browser or operating system update.
It is reported that fake update notifications appeared on the screen when browsers automatically checked the internet connection after users connected to a new Wi-Fi network.
Microsoft claims that the hacker group called Storm-2945 is behind the cyberattack. According to the company, this group is linked to the Midnight Blizzard cyberespionage network and operates on behalf of Russia's Foreign Intelligence Service (SVR).