As cited
Copy frozen at (site build).
threat intel
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Researchers at Microsoft identified a campaign called CaptiveCrunch attributed to Storm-2945, a sub-cluster of the Russian state-sponsored group Midnight Blizzard, that intercepts hotel Wi-Fi traffic to serve fake browser updates delivering CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The malware exploits the trust users place in legitimate software updates when connected to compromised network infrastructure.
Why it matters: Business travelers and remote workers using hotel Wi-Fi face direct surveillance risk from credential theft and data exfiltration; security teams should implement device-level update verification and recommend VPN use on untrusted networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Attackers hijacked hotel Wi-Fi networks to distribute fake browser updates containing CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. Microsoft attributes the operation, tracked as CaptiveCrunch, to Storm-2945, assessed as a sub-cluster of the Russian state-sponsored group Midnight Blizzard.
Why it matters: Business travelers and hotel guests face credential theft and surveillance when connecting to compromised Wi-Fi; practitioners should alert users to verify updates through official channels and disable auto-update prompts on public networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Attackers hijacked hotel Wi-Fi networks to distribute fake browser updates containing CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. Microsoft attributes the operation, tracked as CaptiveCrunch, to Storm-2945, assessed as a sub-cluster of the Russian state-sponsored group Midnight Blizzard.
Why it matters: Business travelers and hotel guests face credential theft and surveillance when connecting to compromised Wi-Fi; practitioners should alert users to verify updates through official channels and disable auto-update prompts on public networks.
- Source published
- First seen by Cybersecurity Tracker