
Hotel Wi-Fi Hijack Delivers CornFlake Spyware Through Fake Updates
Microsoft and ReliaQuest warn that attackers hijack hotel captive portals to serve fake updates, delivering CornFlake RAT (and ChocoShell) via a compromised DNS/gateway, capturing keystrokes, webcam/mic, cookies and tokens. The operation, CaptiveCrunch, is linked to Storm-2945 and attributed to Russia's SVR-linked APT29, though attribution rests on overlapping techniques rather than public corroboration. The initial compromise vector is under investigation; mitigations include using private VPNs, avoiding captive-portal updates, and blocking attacker-authenticated device-code MFA flows via Conditional Access.