Microsoft says hijacked hotel Wi-Fi captive portals were used to push a fake browser or OS update that delivered CornFlake, a RAT capable of stealing webcam images, microphone audio, keystrokes, cookies, and passwords. The activity, tracked as CaptiveCrunch and attributed by Microsoft to Storm-2945, also used device code phishing and ChocoShell token theft to gain access to Microsoft 365 and Azure AD accounts. #CornFlake #CaptiveCrunch #Storm-2945 #MidnightBlizzard #APT29 #CozyBear #ChocoShell #Microsoft365 #AzureAD
Keypoints
- Hijacked hotel Wi-Fi captive portals redirected victims to fake update pages.
- CornFlake RAT captured screenshots, webcam images, microphone audio, and keystrokes.
- Storm-2945 is Microsoftβs attribution for the CaptiveCrunch operation.
- Device code phishing was used to obtain MFA-satisfied access through Microsoft sign-in.
- ChocoShell stole Microsoft 365 and Azure AD tokens from the Token Broker cache.
Read More: https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html