Russian State Actors Target Business Travellers via Hotel Wi-Fi

Russian State Actors Target Business Travellers via Hotel Wi-Fi

•

Episode description

Russian State Actors Target Business Travellers via Hotel Wi-Fi

This episode examines three active threat campaigns with direct SMB relevance. Russian state group APT29 (Midnight Blizzard) is conducting large-scale credential harvesting through compromised hotel and conference Wi-Fi networks across the UK and Europe, specifically targeting business travellers. The operation exploits captive portal authentication flows to harvest Microsoft 365 credentials through spoofed login pages and device code phishing that bypasses MFA. A second campaign demonstrates AI-orchestrated exploitation of PaperCut print management software, progressing from vulnerability research to remote code execution in under four hours across 440+ installations. The episode also covers a maximum-severity GitLab path traversal vulnerability and recent Conti ransomware sentencing. Analysis focuses on the systematic targeting of authentication layers, the operational risk to SMBs from compromised cloud tenancies, and the acceleration of exploit development through AI automation. Practical guidance addresses device code flow controls, conditional access policies, VPN discipline for travelling staff, and the limitations of MFA as a single defensive layer.

Chapters

  • Introduction: Active Campaigns Targeting Business Travellers Overview of Russian state-sponsored credential harvesting via UK hotel Wi-Fi networks and AI-orchestrated PaperCut exploitation campaign. Episode positions APT29 activity as immediate SMB threat rather than purely government-sector concern.
  • CaptiveCrunch: APT29 Hotel Wi-Fi Credential Harvesting Detailed analysis of Midnight Blizzard (APT29) campaign exploiting captive portal networks at hotels and conferences. Explains device code phishing technique that bypasses MFA, SMB impact from compromised Microsoft 365 tenancies, and four immediate mitigation actions including device code flow controls and conditional access policies.
  • Call to Action Listener engagement request to follow show and share briefing given active campaign status.
  • AI-Orchestrated PaperCut Exploitation Analysis of CVE-2026-81578 and CVE-2026-82078 exploitation campaign against PaperCut print management software. Details AI agent automation achieving remote code execution in under four hours across 440+ targets. Provides specific guidance on patch verification, internet exposure assessment, and compromise indicators.
  • GitLab Vulnerability and Conti Sentencing Brief coverage of CVE-2026-85706 maximum-severity GitLab path traversal vulnerability requiring immediate patching. Notes Ukrainian national receiving four-year sentence for Conti ransomware development, with analysis positioning outcome as illustrating enforcement limitations rather than meaningful deterrent.
  • The Wider Pattern: Authentication Layer Under Systematic Attack Synthesis identifying authentication layer as common target across multiple active campaigns. Argues current threat landscape reflects prioritisation failure rather than technology limitation, given documented NCSC guidance on phishing-resistant MFA and conditional access controls.
  • Closing: Practical Takeaways Summary of actionable guidance: disable unnecessary device code flow, patch PaperCut installations, brief travelling staff on captive portal risks before conference season.

Links

No chapters are available for this episode.