A new hacking campaign, known as CaptiveCrunch, is targeting wireless networks at hotels, conference centers, airports, and other hospitality venues in an attempt to steal credentials and compromise devices. This campaign is using captive portal prompts to phish sensitive information and spread malware. Users are accustomed to seeing these pop-ups when logging onto public networks, so they're less likely to be suspicious. The hackers are able to manipulate DNS and HTTP traffic from these portals, which allows them to send users to phishing sites and harvest login credentials and device codes.
When connecting to hotel or airport wifi, users may see a number of fake dialog boxes, such as a Windows Update or Windows Security window or a prompt to download a PDF viewer or disk optimization utility. These prompts are designed to trick users into revealing sensitive information or downloading malware. To avoid falling victim to these attacks, it's essential to be cautious when using public wifi. Users should assume that public and guest wireless networks at hotels, conference centers, and airports are untrustworthy and rely on private connections instead.
Whenever possible, users should rely on private connections, such as mobile hotspots and cellular data, instead of logging onto public wifi. If a user must use hotel or airport wifi, it's recommended to use a VPN with a killswitch, which blocks internet traffic if the connection drops unexpectedly. Users should also inspect login pop-ups carefully and be wary of portal pages that ask for information beyond a room number or last name in order to connect. Additionally, users should never download software or browser updates, certificates, tools, or utilities through captive portals, pop-up messages, or web prompts.
To further protect themselves, users should ensure their devices, apps, and software are up to date before traveling to patch security flaws and minimize the likelihood that they'll need to download anything while on the road. If a user is prompted to copy code or run commands on their device, they should exit immediately, as this is a sign of a ClickFix attack. Any urgent prompts, such as a countdown timer, are also a red flag. By taking these precautions, users can reduce the risk of falling victim to public wifi attacks and keep their devices safe.
For users on work devices, it's recommended to have an enterprise-managed travel router or hotspot that provides an encrypted connection to the company's infrastructure. This can provide an additional layer of security and protect against potential threats. By being aware of the risks associated with public wifi and taking steps to protect themselves, users can stay safe and secure while traveling. It's essential to remain vigilant and cautious when using public wifi, as the risks of hacking and malware are very real.