CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 3672

As cited

Citation snapshot as of .

threat intel

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Researchers at Microsoft identified a campaign called CaptiveCrunch attributed to Storm-2945, a sub-cluster of the Russian state-sponsored group Midnight Blizzard, that intercepts hotel Wi-Fi traffic to serve fake browser updates delivering CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The malware exploits the trust users place in legitimate software updates when connected to compromised network infrastructure.

Why it matters: Business travelers and remote workers using hotel Wi-Fi face direct surveillance risk from credential theft and data exfiltration; security teams should implement device-level update verification and recommend VPN use on untrusted networks.

Source published
First seen by Cybersecurity Tracker

Source attribution