The Register Home Page

back to article Russian spies turn public Wi-Fi into malware delivery systems

Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are compromising captive portal networks to deliver infostealers, keyloggers, and other malware. With the help of ReliaQuest's earlier work, Redmond fingered Storm-2945, a …

  1. Headley_Grange Silver badge

    You'll likely be safer if you've got an Apple device. I've never had one that didn't have problems connecting to captive WiFi services - usually when I desperately needed to be connected and had no mobile signal.

    1. Dan 55 Silver badge

      It seems the WiFi portal page is turned evil, so when you connect you have to hope your browser is resistant against whatever malware is thrown its way by Russia, then your phone and all your apps are resistant to MITM and DNS poisoning.

    2. Anonymous Coward
      Anonymous Coward

      You'll likely be safer if you've got an Apple device

      .. until you use it to access Microsoft resources ..

  2. Jou (Mxyzptlk) Silver badge

    Again OAuth...

    MFA "circumvented". Again. Way too easy to fake it. Again. This feels so much like an implementation flaw. Again.

  3. Anonymous Coward
    Anonymous Coward

    Those no good commie baskets :o

    Those no good commie baskets. Is there no end to their iniquity :o

    1. Anonymous Coward
      Anonymous Coward

      Re: Those no good commie baskets :o

      I thought Russia was our best friend now? Unlike those no-good Canadians, very bad people, and the Evil Greenlanders and the commie Minnesotans

  4. anothercynic Silver badge

    OpenRoaming?

    This is something this OpenRoaming malarkey could resolve, given that authentication is done by WPA-Enterprise, not some captive portal page.

    Although, now that I am looking at it, even that would have a problem if they use a feature called CapPort (which stands for Captive Portal).

  5. Anonymous Coward
    Anonymous Coward

    Nice deflection (as always)

    The main takeaway, in Microsoft's book, is to stop trusting public Wi-Fi Microsoft so much.

    There. Fixed it for you.

    As for the issue at hand, use VPN and ensure your company has set geographic monitoring tight. If you're logged in via VPN you'll appear local, the stolen token will come from somewhere else which should normally produce an alarm and - if set up - protective measures.

    That said, token theft is a swine to prevent. I once heard rumours that Microsoft is working on something that ties the token to the specific browser, but that was at least half a year ago if not longer so I'm guessing they didn't get it to work properly. Quelle surprise..

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon