Hotel Wi-Fi Used to Spread Surveillance RAT via Fake Browser Updates
Attackers hijacked hotel Wi-Fi networks to push fake browser updates that installed CornFlake malware. The campaign, tracked as CaptiveCrunch, is linked to the threat group Storm-2945.
TL;DR
- Fake browser updates delivered over compromised hotel Wi-Fi networks.
- Malware installed is CornFlake, a RAT capable of capturing webcam, mic, and keystrokes.
- Campaign named CaptiveCrunch, attributed to threat group Storm-2945.
- Storm-2945 is considered a sub-cluster of the Midnight Blizzard cluster.
- Targeting likely includes business travelers and high-value network access.
Cybercriminals have exploited the trust users place in public Wi-Fi by hijacking hotel networks to distribute malicious payloads disguised as legitimate browser updates. According to Microsoft's latest threat intelligence report, these attacks have been used to deploy CornFlake, a sophisticated remote access trojan (RAT) designed for covert surveillance.
The operation, dubbed CaptiveCrunch, has been attributed to a threat actor cluster known as Storm-2945, which researchers believe operates under the broader Midnight Blizzard umbrella. These findings underscore the persistent risks associated with unsecured public networks, particularly in high-traffic environments like hotels where business travelers may access sensitive corporate data.
Malware Capabilities and Delivery Method
- CornFlake RAT enables attackers to capture webcam images, record microphone audio, and log keystrokes.
- Infection occurs through fake browser update prompts pushed automatically over compromised Wi-Fi networks.
- No user interaction required beyond connecting to the infected network.
- Payloads are designed to maintain persistence and evade standard endpoint detection tools.
Attribution and Threat Actor Background
- Microsoft tracks the campaign as CaptiveCrunch, active since early 2026.
- Storm-2945 is identified as the primary operator behind the attacks.
- Researchers assess Storm-2945 as an operational sub-cluster of Midnight Blizzard (aka APT29 or Nobelium).
- Midnight Blizzard has historically targeted government entities, think tanks, and technology firms.
- Tactics suggest possible state-sponsored motivation or advanced cybercrime operations.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.