Russian state-sponsored hackers have launched a campaign targeting hotel Wi-Fi networks to hijack active cloud sessions, bypassing traditional multi-factor authentication protections. According to research from Microsoft, the threat group tracked as Midnight Blizzard (APT29) is deploying custom malware dubbed "Grasshopper" to intercept authentication tokens from traveling executives.

The attack shifts focus from user deception via phishing to exploiting the trusted network environments of hotels. By compromising local Wi-Fi infrastructure, attackers can monitor traffic from connected devices and extract active session cookies for services like Microsoft 365. These cookies represent already-authenticated browser sessions, granting adversaries direct access to corporate email, files, and data without triggering a new login prompt that would require a second authentication factor.

This approach effectively turns public hospitality networks into attack infrastructure outside corporate control. An organization's cloud security now partially depends on the network integrity of third-party hotels—venues that IT teams cannot directly secure. The campaign underscores a persistent vulnerability in cloud identity systems that rely on session tokens for continuous access.

Mitigation requires a layered, zero-trust posture that treats all public Wi-Fi as hostile. Security experts recommend enforcing always-on VPNs on all company devices to encrypt traffic and route it through trusted infrastructure. Endpoint Detection and Response (EDR) systems should be configured to identify the Grasshopper malware and flag suspicious network activity. Organizations are also urged to accelerate adoption of phishing-resistant authentication such as FIDO2 keys or passkeys, which are immune to session hijacking because they require cryptographic proof of possession rather than reusable tokens.

The campaign highlights how the corporate attack surface has expanded beyond digital perimeters into the physical infrastructure of everyday travel. Adversaries are increasingly adapting tactics to target traveler behavior and leverage implicit trust in venue networks. For security teams, the message is clear: audit travel security policies, treat every external connection as a potential pivot point, and prioritize hardware-backed authentication over legacy token-based systems.


俄羅斯國家支持的黑客發動了一項攻勢,針對酒店Wi-Fi網絡以劫持活躍的雲端環節,繞過傳統多因素認證保護。根據微軟的研究,被追蹤為 Midnight Blizzard(APT29)的威脅組織正在部署名為「Grasshopper」的定制惡意軟件,以截取外訪企業高管的認證令牌。

這次攻擊將焦點從透過網絡釣魚欺騙用戶,轉移到利用酒店的受信任網絡環境。透過入侵本地Wi-Fi基礎設施,攻擊者可監控已連接設備的流量,並提取用於 Microsoft 365 等服務的活躍環節 Cookie。這些 Cookie 代表已認證的瀏覽器環節,授予對手直接訪問企業電郵、文件和數據的權限,且不會觸發需要第二重認證因素的新登入提示。

這種方法有效地將公共酒店網絡轉化為企業控制之外的攻擊基礎設施。組織的雲端安全性如今部分取決於第三方酒店的網絡完整性——而這些場所正是IT團隊無法直接確保安全的地方。這場攻勢突顯了依賴環節令牌以獲得持續訪問權限的雲端身份系統中一個持續存在的漏洞。

緩解措施需要採用分層的零信任姿態,假設所有公共 Wi-Fi 均具敵意。安全專家建議在所有公司設備上強制啟用始終開啟的 VPN,以加密流量並透過受信任的基礎設施進行路由。Endpoint Detection and Response (EDR) 系統應經過配置以識別 Grasshopper 惡意軟件並標記可疑網絡活動。組織也應加速採用防釣魚認證機制,如 FIDO2 密匙或通行密鑰,這些機制對環節劫持免疫,因為它們要求密碼學上的擁有權證明,而非可重用的令牌。

這場攻勢突顯了企業攻擊面如何擴展到數碼邊界之外,深入日常旅行的實體基礎設施。對手正越來越多地調整策略,以針對旅行者行為並利用場所網絡中的隱含信任。對安全團隊而言,資訊很明確:審核旅行安全政策,將每個外部連接視為潛在樞紐點,並優先採用硬件支持的認證機制而非傳統的基於令牌的系統。

新聞來源 / Original News Source