Hijacked Hotel Wi-Fi Pushes CornFlake Spyware Updates

Microsoft Threat Intelligence is warning that hijacked hotel and hospitality Wi-Fi captive portals are being abused to push fake browser and operating system updates that install CornFlake, a full-featured Windows remote access trojan, in a global campaign targeting travelers worldwide[1][2][5]. The operation, which Microsoft tracks as CaptiveCrunch, combines traffic manipulation with social engineering to compromise guests’ devices as soon as they connect to captive portals for internet access[1][3][6].

Microsoft assesses the activity to be carried out by Storm-2945, an operational sub-cluster of the Russian state-linked group Midnight Blizzard, also known as APT29 and Cozy Bear[1][2][10]. The U.S. and U.K. governments have previously attributed Midnight Blizzard to Russia’s Foreign Intelligence Service (SVR), framing CaptiveCrunch as part of a broader cloud-focused espionage apparatus rather than purely financially motivated crime[2][5][10]. According to Microsoft, Storm-2945 has been conducting widespread but targeted attacks against hospitality networks served by captive portals since early May 2026, focusing on travelers’ Microsoft 365 and cloud credentials alongside malware delivery[1][3][6].

CornFlake is a Go-based Windows implant that initially runs in dropper mode, presenting a convincing fake progress window while copying itself to the %APPDATA%svchost32svchost32.exe path and registering a service under the display name Cloud Sync Service for persistence[1][2][3]. Once established, the RAT can capture webcam images and microphone audio, log keystrokes, take idle-triggered screenshots, and record clipboard contents along with the active window title, giving operators extensive insight into a victim’s activity[1][2][3]. It also steals browser cookies and saved passwords, including cookies protected by Chrome’s App-Bound Encryption, monitors removable media, opens a remote shell, and uses both Registry Run keys and scheduled tasks backed by a watchdog mechanism to restore persistence if defenders remove it[1][2][3]. Microsoft notes that CornFlake exposes a localhost HTTP API, turning the implant into a modular platform that can be extended with companion payloads such as the ChocoShell in-memory PowerShell stealer focused on credential and token theft[1][2][3].

In CaptiveCrunch, Storm-2945 leverages its position inside hotel and hospitality networks to manipulate DNS and HTTP traffic from captive portals, inserting adversary-in-the-middle infrastructure that can redirect travelers either to phishing sites or to fake update download flows[1][3][5]. The actor has been observed using doppelganger domains that closely resemble legitimate Microsoft properties and abusing device code authentication against Microsoft Entra ID to harvest Microsoft 365 credentials and cloud access tokens[1][3][6]. By blending this cloud-focused phishing with CornFlake and ChocoShell deployments, the campaign aims to secure long-term surveillance footholds on endpoints while simultaneously expanding access into victims’ corporate and government cloud environments[1][3][5].

There are no widely disclosed product vulnerabilities or CVE identifiers associated with CaptiveCrunch to date, underscoring that the campaign succeeds primarily through control of hospitality infrastructure and convincing social engineering rather than exploiting new browser or operating system flaws[1][2][5]. Microsoft has published detection guidance, hunting queries, and indicators of compromise for CornFlake and related tooling, and recommends that organizations monitoring traveler traffic pay particular attention to anomalous captive portal behavior, unexpected services such as svchost32 running under user profiles, and suspicious localhost HTTP listeners[1][3][6]. Travelers can reduce exposure by avoiding software updates offered via captive portals, installing patches only through built-in browser and operating system update mechanisms, and treating any unsolicited update prompts over public Wi-Fi as potential malware, in line with broader guidance on fake-update schemes from security teams and network providers[1][2][8].

References

  1. CaptiveCrunch: Midnight Blizzard targets travelers worldwide for …
  2. Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance …
  3. Midnight Blizzard targets travelers worldwide for malware …
  4. CaptiveCrunch Archives – Security Affairs
  5. Post
  6. Browser “Fake Updates” Malware Scheme | AT&T Cyber Aware
  7. Midnight Blizzard (NOBELIUM) | Nation State Actors

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply