Tezzbuzz Desk- Microsoft has warned travelers about hotel and public Wi-Fi networks. Cyber criminals are trying to deliver malware to users' devices through fake login pages and fake software updates.
If you use Wi-Fi in a hotel, conference center, airport or any other public place during travel, then you need to be a little more cautious. Microsoft has detected a cyber campaign in which hackers are taking advantage of shared Wi-Fi networks to direct users to fake websites and fake login pages. Through this, passwords, account details and other sensitive information can be stolen.
According to Microsoft Threat Intelligence, such activities have been observed in some networks to the hospitality sector since the beginning of May 2026. Places like hotels and conference centers often require users to visit a login page or agree to certain rules before using the Internet.
Hackers are taking advantage of this system. By tampering with the DNS and web traffic of the network, the user can be sent to a fake page instead of the real website. These pages may appear to be genuine and may ask the user to enter a Microsoft account or other login information.
The second method of cyber attack is even more dangerous. The user may suddenly be shown a message on the screen that an update of Windows, browser or any security software is available. After this he is asked to download or install the update. If the user downloads this file without checking it, then dangerous malware can reach his system. Microsoft has linked this activity to Storm-2945. During the investigation, Windows based Remote Access Trojan i.e. RAT named CornFlake has also been detected.
Once CornFlake reaches the infected device, attackers can try to obtain many types of sensitive information. This may include files, passwords, and session information. Apart from this, activities like recording the information typed on the keyboard and gaining remote access to the system can also be done.
Malware can adopt different methods to embed itself in the system and try to appear as a legitimate Windows service or process. In such a situation, it may be difficult for the user to detect it during normal use.
The threat is said to be not limited to Windows computers only. Microsoft has received indications that similar technology could also target people using Android devices. In some cases the user may be asked to download and install an Android APK file on a website. If the user installs such a file without verifying the source, the security of the phone may be at risk.
According to Microsoft, corporate travelers are particularly likely to be targeted in such attacks. Through hotel and other public Wi-Fi networks, attackers can try to access people whose devices contain work emails, cloud accounts, important documents, and other sensitive data.
That is, the hotel's Wi-Fi definitely provides free internet facility, but even a little carelessness to avoid cyber attacks under its cover can prove costly.