
The SVR's shift from router exploitation (the APT28 campaign NCSC warned about in April) to hotel captive portal compromise suggests Russian intelligence is adapting to patched edge devices by moving one layer up the stack — hotels rarely segment guest networks or monitor for credential phishing at the portal layer, and most corporate travel policies still permit Wi-Fi use with VPN as the sole mitigation.
Corporate travelers using hotel Wi-Fi in these three countries now face credential theft that bypasses endpoint security — the attack happens at the network layer before VPNs activate, and Microsoft 365 tokens stolen via ChocoShell grant access to cloud environments that perimeter defenses assume are already authenticated.
Conference centers are confirmed targets, which puts defense-industry executives, government contractors, and venture investors attending industry events in the direct path of SVR collection. Watch whether CISA issues emergency guidance on hotel network use for cleared personnel — silence past mid-August would signal the interagency assessment is that existing travel security protocols already cover this threat.
How many organizations have confirmed compromised credentials from this campaign, and has Microsoft observed any follow-on intrusions using the stolen tokens?
Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.