A cyberattack campaign targeting hotel Wi-Fi networks has been uncovered by researchers from Microsoft and ReliaQuest. Named CaptiveCrunch, the attack is attributed to a Russian state-sponsored group known as Midnight Blizzard. Instead of directly targeting employees' computers, hackers are focusing on the routers and login portals of hotels and conference centers. By gaining control of the network gateway, attackers are manipulating the Domain Name System (DNS), which translates website names into IP addresses, to redirect employees' web traffic to malicious servers. Once the traffic is intercepted, hackers deploy advanced techniques to compromise devices. These include social engineering tactics like ClickFix, which trick users into running fake system or network updates. These deceptive updates install malicious software such as CornFlake, a type of Trojan, or ChocoShell, which can record keyboard inputs, activate microphones, and steal browser cookies. These tools allow attackers to gather sensitive information without needing to access passwords directly. In addition to these methods, hackers are also exploiting Microsoft Entra ID, a service used for user authentication. By breaching this system, they are obtaining valid OAuth tokens, which allow access to corporate resources, and bypassing multi-factor authentication without ever seeing passwords in plain text. This makes the attack particularly dangerous, as it circumvents traditional security measures that rely on password interception. For corporate leaders and IT managers, the key takeaway is that conventional DNS protections on individual workstations are no longer sufficient. Attackers are now manipulating DNS at the network level, making traditional defenses ineffective. To protect traveling staff and company data, it's essential to enforce the use of a Virtual Private Network (VPN) on all company devices. A VPN ensures that all traffic, including DNS queries, is encrypted and routed through a secure network. Additional measures, such as blocking the device code authentication flow in Entra ID through access policies and disabling the WPAD protocol on Windows devices, are also recommended to prevent similar attacks.