Microsoft: Russian Hackers Leveraging AI to Automate Global Hotel Cyberattacks

cyb3rops · x · 2026-08-01

Microsoft Security Blog detailed a widespread traffic manipulation campaign by the Russian threat actor Midnight Blizzard targeting travelers at hotels worldwide.

Dubbed CaptiveCrunch, the operation has been active since early May 2026. It exploits captive portals to manipulate DNS and HTTP traffic, redirecting users to attacker-controlled infrastructure to deliver malware or intercept authentication flows.

Crucially, the report notes that the group is using AI to support a significant portion of their operations, allowing their techniques and infrastructure to move and change dynamically at an unprecedented pace.

Original post →

More from Safety

Safety channel →