FAULT LINES
Signals That Move Strategy
Tech Frontiers · Americas · Cyber

SVR-Linked Hackers Compromise Hotel Wi-Fi in US, India, Saudi Arabia Using Fake Login Pages

Russian state-sponsored hackers linked to the SVR have been compromising hotel Wi-Fi networks in the US, India, and Saudi Arabia since early May to steal credentials and deploy espionage malware, Microsoft reported August 2. The campaign uses fake Microsoft login pages and fraudulent update screens to deliver CornFlake, a remote access trojan enabling persistent control, and ChocoShell, an information stealer targeting cloud credentials.
AI synthesis, editor-reviewed · 1 source · August 03, 2026
Photo: The Record (Recorded Future)

The SVR's shift from router exploitation (the APT28 campaign NCSC warned about in April) to hotel captive portal compromise suggests Russian intelligence is adapting to patched edge devices by moving one layer up the stack — hotels rarely segment guest networks or monitor for credential phishing at the portal layer, and most corporate travel policies still permit Wi-Fi use with VPN as the sole mitigation.

WHY IT MATTERS

Corporate travelers using hotel Wi-Fi in these three countries now face credential theft that bypasses endpoint security — the attack happens at the network layer before VPNs activate, and Microsoft 365 tokens stolen via ChocoShell grant access to cloud environments that perimeter defenses assume are already authenticated.

Conference centers are confirmed targets, which puts defense-industry executives, government contractors, and venture investors attending industry events in the direct path of SVR collection. Watch whether CISA issues emergency guidance on hotel network use for cleared personnel — silence past mid-August would signal the interagency assessment is that existing travel security protocols already cover this threat.

WHAT THIS DOESN’T TELL US

How many organizations have confirmed compromised credentials from this campaign, and has Microsoft observed any follow-on intrusions using the stolen tokens?

Sources: The Record (Recorded Future)
LinkedInX

Fault Lines

Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.

Front page → Get the weekly brief →