Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.

Microsoft links hijacked hotel Wi-Fi to fake updates that deliver CornFlake, steal cloud tokens, and abuse device codes to target travelers.

Microsoft blames Russian state-sponsored APT Midnight Blizzard for hacking hotel Wi-Fi networks to steal travelers’ credentials.