On July 31, Microsoft disclosed that Storm-2945 — a subdivision of the Russian SVR-linked actor tracked as Midnight Blizzard — had compromised captive-portal networks at hotels and conference centers, manipulating traffic to push malware disguised as operating-system updates, alongside device-code phishing. Per Microsoft and reporting in The Register, the campaign began around February 2026, with traffic manipulation observed since early May. The tooling is purpose-built for surveillance: a Windows implant with keylogging and audio capture, and an in-memory infostealer that takes browser cookies, passwords, single-sign-on tokens, and saved Wi-Fi credentials.
Read the target set, not just the technique. Hotel and conference networks select for exactly the people an intelligence service wants: executives, engineers, officials, and researchers — away from their corporate network's protections, on deadline, clicking through whatever the portal shows them.
Most travel-risk programs are built around physical hazards — crime, unrest, weather, medical. This campaign is a reminder that for organizations with intellectual property or government work, the more persistent traveler threat is collection. A briefing that covers pickpockets but not device hygiene, network behavior, and foreign-intelligence targeting patterns for the destination is briefing for the wrong decade.
- Pre-travel: briefings should be generated per trip, from live intelligence — including known targeting activity relevant to the traveler's role and destination — not from a static country sheet.
- In travel: assume hostile networks. Corporate devices on hotel Wi-Fi without a trusted tunnel are collection opportunities; “update” prompts on captive portals are the attack.
- Post-travel: high-exposure trips deserve a debrief and, where warranted, device review — the point where travel security hands findings to counterintelligence.
PATHWAY — Travel Security is built on that model: automated, intelligence-driven briefings for every trip — including foreign-intelligence targeting where it applies — with risk scoring that decides when a human analyst steps in, and mandatory debriefs on the highest-risk travel. Briefing generation is designed to save analysts two to four hours per traveler, which is what makes covering every trip, not just the famous ones, feasible.
Governance
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
The SVR did not breach a headquarters for this campaign. It waited for the workforce to walk out the door. Travel programs should assume that trade is now standard.
- Microsoftthe disclosed campaign and tooling
- The Registerreporting on the campaign