AUTO-UPDATED

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Russian-linked threat actor Storm-2945 is compromising hotel Wi-Fi networks to deliver the CornFlake remote access trojan through fake browser updates and malicious captive portal redirects.

Key Points

  • Microsoft attributes the CaptiveCrunch operation to Storm-2945, a sub-cluster of the Russian state-sponsored group Midnight Blizzard.
  • Attackers hijack hotel Wi-Fi gateways to forge DNS responses, redirecting users to fake update pages that prompt manual malware execution.
  • The CornFlake trojan captures webcam images, microphone audio, keystrokes, browser cookies, and saved passwords from infected Windows devices.
  • Attackers are also using Microsoft device code authentication flows to bypass multi-factor authentication and steal session tokens.
  • Security researchers recommend using full-tunnel VPNs and avoiding any software updates or security prompts encountered on public captive portals.

Why it Matters

This campaign highlights a significant vulnerability in hospitality network infrastructure that allows attackers to intercept traffic and compromise high-value targets. By exploiting trust in captive portals, threat actors can gain persistent access to corporate devices and bypass standard multi-factor authentication protections.
Internet Published by info@thehackernews.com (The Hacker News)
Read original