Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft says hijacked hotel Wi-Fi captive portals were used to push a fake browser or OS update that delivered CornFlake, a RAT capable of stealing webcam images, microphone audio, keystrokes, cookies, and passwords. The activity, tracked as CaptiveCrunch and attributed by Microsoft to Storm-2945, also used device code phishing and ChocoShell token theft to gain access to Microsoft 365 and Azure AD accounts. #CornFlake #CaptiveCrunch #Storm-2945 #MidnightBlizzard #APT29 #CozyBear #ChocoShell #Microsoft365 #AzureAD

Keypoints

  • Hijacked hotel Wi-Fi captive portals redirected victims to fake update pages.
  • CornFlake RAT captured screenshots, webcam images, microphone audio, and keystrokes.
  • Storm-2945 is Microsoft’s attribution for the CaptiveCrunch operation.
  • Device code phishing was used to obtain MFA-satisfied access through Microsoft sign-in.
  • ChocoShell stole Microsoft 365 and Azure AD tokens from the Token Broker cache.

Read More: https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html