By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hotel Wi-Fi Hijacked for Surveillance Malware Delivery

Attackers have been observed hijacking hotel Wi-Fi networks to distribute a sophisticated surveillance malware known as CornFlake, according to a recent report from Microsoft. This operation, tracked by researchers as CaptiveCrunch, utilizes fake browser update prompts to trick users into downloading the malicious software. CornFlake is a remote access trojan (RAT) designed to steal sensitive user data, including webcam imagery, microphone audio recordings, and keystrokes. The report attributes the campaign to a threat actor identified as Storm-2945, which Microsoft assesses to be an operational sub-cluster of the larger group Midnight Blizzard. Midnight Blizzard is also known by the alias Nobelium, a group previously linked to state-sponsored cyber espionage activities, particularly targeting government entities and critical infrastructure. The CaptiveCrunch operation specifically targets individuals who connect to public Wi-Fi networks in hotels, a common scenario for business travelers and tourists. By compromising the Wi-Fi infrastructure, the attackers can intercept and manipulate network traffic, enabling them to inject malicious content like the fake browser update. This method bypasses traditional security measures that might be in place on individual devices, as the threat originates from the network itself. The fake update appears legitimate to the user, prompting them to install it to ensure optimal browsing experience, thereby gaining access to their device. Once installed, CornFlake establishes a persistent presence, allowing the attackers to remotely control the infected device and exfiltrate data without the user's knowledge. The capabilities of CornFlake are extensive, enabling covert surveillance through the device's built-in sensors and logging all user input. This type of attack highlights the growing sophistication of cyber threats targeting mobile users and the vulnerabilities inherent in public network infrastructure. The involvement of a group assessed to be linked to Midnight Blizzard suggests a potential focus on espionage, aiming to gather intelligence on individuals or organizations passing through these compromised locations. Microsoft's research into CaptiveCrunch underscores the importance of network security awareness, especially when connecting to untrusted public Wi-Fi. Users are advised to exercise extreme caution and verify the authenticity of any software updates prompted on public networks, and ideally, to use a Virtual Private Network (VPN) to encrypt their traffic and mitigate such risks. The ongoing efforts by threat actors like Storm-2945 to leverage compromised network access for malware distribution represent a significant challenge for cybersecurity professionals and end-users alike, demanding continuous vigilance and robust security practices.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.