Hotel Wi-Fi Hijack Delivers CornFlake Spyware Through Fake Updates

TL;DR Summary
Microsoft and ReliaQuest warn that attackers hijack hotel captive portals to serve fake updates, delivering CornFlake RAT (and ChocoShell) via a compromised DNS/gateway, capturing keystrokes, webcam/mic, cookies and tokens. The operation, CaptiveCrunch, is linked to Storm-2945 and attributed to Russia's SVR-linked APT29, though attribution rests on overlapping techniques rather than public corroboration. The initial compromise vector is under investigation; mitigations include using private VPNs, avoiding captive-portal updates, and blocking attacker-authenticated device-code MFA flows via Conditional Access.
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware The Hacker News
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft microsoft.com
- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts BleepingComputer
- Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials securityaffairs.com
- TSA warns you about fake airport Wi-Fi Komando.com
Reading Insights
Total Reads
0
Unique Readers
7
Time Saved
3 min
vs 4 min read
Condensed
89%
684 → 76 words
Want the full story? Read the original article
Read on The Hacker News