“Organizations should assume that public and hospitality network infrastructure might not be trustworthy,” Microsoft warned Friday, marking a notable hardening of its security advice for business travelers. A new hacking threat attributed to Russian threat actors “targets travelers worldwide for malware delivery and credential theft."

The warning follows the discovery of CaptiveCrunch, a global campaign attributed by Microsoft to Storm-2945, a sub-cluster of Russia’s Midnight Blizzard. The campaign targets corporate travelers with credential theft and malware delivered through compromised guest networks.

Microsoft says the activity has been under way since early May, involving hospitality networks and other guest networks served by captive portals worldwide.

Its warning follows a July report from ReliaQuest , which found attackers targeting Microsoft 365 users through compromised Wi-Fi gateways. By manipulating network traffic, the attackers redirect guests to fake sign-in pages without first sending a phishing email or compromising the PC.

In a timely twist given recent concerns about the use of AI in cyberattacks, Microsoft Threat Intelligence thanked Anthropic and OpenAI for their “collaboration and support during this investigation.” Microsoft says Storm-2945 used AI to support the threat campaign.

“In addition to variants of malware targeting Windows systems,” Microsoft says it is “also aware of indications that the threat actor might be targeting Android devices with similar techniques as the ClickFix landings also include instructions for Android devices to download and install an APK file.”

The attackers compromise hospitality infrastructure to display fake verification checks, sign-in prompts and software updates. Because these pages appear while users are connecting through a hotel or venue’s legitimate Wi-Fi gateway, the deception is difficult for users to recognize.

Some victims are directed to Microsoft’s legitimate device-code authentication process. The attacker initiates a sign-in attempt and persuades the victim to enter an attacker-supplied code. If the victim approves the request, Microsoft issues valid authentication tokens to enable access to the victim’s account without needing to steal a password or directly bypass multi-factor authentication.

While ReliaQuest’s research centered on credential theft, Microsoft reports that the attacks can deliver malware directly to victims’ devices, significantly broadening the threat. The campaign can also deliver malware disguised as Windows updates.

Microsoft has named the Windows remote-access trojan CornFlake. The RAT is designed to steal credentials and session tokens, record keystrokes, collect files and capture screenshots. It can also hijack a device’s audio and video capabilities for surveillance, and give attackers persistent access.

Microsoft advises travelers to treat hotel, conference, airport and other guest networks as untrusted. It recommends using mobile hotspots, cellular connections or other private connectivity, avoiding updates through captive portals, strengthening Conditional Access and phishing-resistant authentication and also blocking device-code authentication when not required.