← Back to blog

Hotel Wi-Fi Used to Spread Surveillance RAT via Fake Browser Updates

Attackers hijacked hotel Wi-Fi networks to push fake browser updates that installed CornFlake malware. The campaign, tracked as CaptiveCrunch, is linked to the threat group Storm-2945.

TL;DR

  • Fake browser updates delivered over compromised hotel Wi-Fi networks.
  • Malware installed is CornFlake, a RAT capable of capturing webcam, mic, and keystrokes.
  • Campaign named CaptiveCrunch, attributed to threat group Storm-2945.
  • Storm-2945 is considered a sub-cluster of the Midnight Blizzard cluster.
  • Targeting likely includes business travelers and high-value network access.

Cybercriminals have exploited the trust users place in public Wi-Fi by hijacking hotel networks to distribute malicious payloads disguised as legitimate browser updates. According to Microsoft's latest threat intelligence report, these attacks have been used to deploy CornFlake, a sophisticated remote access trojan (RAT) designed for covert surveillance.

The operation, dubbed CaptiveCrunch, has been attributed to a threat actor cluster known as Storm-2945, which researchers believe operates under the broader Midnight Blizzard umbrella. These findings underscore the persistent risks associated with unsecured public networks, particularly in high-traffic environments like hotels where business travelers may access sensitive corporate data.

Malware Capabilities and Delivery Method

  • CornFlake RAT enables attackers to capture webcam images, record microphone audio, and log keystrokes.
  • Infection occurs through fake browser update prompts pushed automatically over compromised Wi-Fi networks.
  • No user interaction required beyond connecting to the infected network.
  • Payloads are designed to maintain persistence and evade standard endpoint detection tools.

Attribution and Threat Actor Background

  • Microsoft tracks the campaign as CaptiveCrunch, active since early 2026.
  • Storm-2945 is identified as the primary operator behind the attacks.
  • Researchers assess Storm-2945 as an operational sub-cluster of Midnight Blizzard (aka APT29 or Nobelium).
  • Midnight Blizzard has historically targeted government entities, think tanks, and technology firms.
  • Tactics suggest possible state-sponsored motivation or advanced cybercrime operations.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Hotel Wi-Fi Used to Spread Surveillance RAT via Fake Browser Updates — Agent Breach Blog | Agent Breach