Russian foreign intelligence operatives, specifically the Storm-2945 subdivision of the SVR's Midnight Blizzard, have been compromising public Wi-Fi networks to deliver malware such as infostealers and keyloggers. This campaign, which targets users of public Wi-Fi in hotels, conference centers, and other shared venues, has been uncovered by Microsoft with the help of ReliaQuest's earlier research1. The attackers are using captive portal networks to spread the malware, putting users' sensitive information at risk. The fact that state-aligned actors are involved in this campaign shifts the threat model from criminal to geopolitical, requiring a different approach to mitigation. This development is significant because it highlights the increasing use of public Wi-Fi networks as a vector for cyber attacks, making it essential for users to exercise caution when connecting to these networks. So what matters to practitioners is that they must now consider the geopolitical implications of such attacks and adjust their security strategies accordingly.
Russian spies turn public Wi-Fi into malware delivery systems
⚠️ Critical Alert
Why This Matters
State-aligned activity involving Microsoft shifts the threat model from criminal to geopolitical — different playbook required.
References
- The Register. (2026, August 3). Russian spies turn public Wi-Fi into malware delivery systems. *The Register*. https://www.theregister.com/security/2026/08/03/russias-svr-borks-public-wi-fis-for-digital-surveillance/5282399
Original Source
The Register
Read original →