Russian-linked threat actor Storm-2945 is compromising hotel Wi-Fi networks to deliver the CornFlake remote access trojan through fake browser updates and malicious captive portal redirects.
Key Points
- Microsoft attributes the CaptiveCrunch operation to Storm-2945, a sub-cluster of the Russian state-sponsored group Midnight Blizzard.
- Attackers hijack hotel Wi-Fi gateways to forge DNS responses, redirecting users to fake update pages that prompt manual malware execution.
- The CornFlake trojan captures webcam images, microphone audio, keystrokes, browser cookies, and saved passwords from infected Windows devices.
- Attackers are also using Microsoft device code authentication flows to bypass multi-factor authentication and steal session tokens.
- Security researchers recommend using full-tunnel VPNs and avoiding any software updates or security prompts encountered on public captive portals.