As cited
Citation snapshot as of .
threat intel
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Researchers at Microsoft identified a campaign called CaptiveCrunch attributed to Storm-2945, a sub-cluster of the Russian state-sponsored group Midnight Blizzard, that intercepts hotel Wi-Fi traffic to serve fake browser updates delivering CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The malware exploits the trust users place in legitimate software updates when connected to compromised network infrastructure.
Why it matters: Business travelers and remote workers using hotel Wi-Fi face direct surveillance risk from credential theft and data exfiltration; security teams should implement device-level update verification and recommend VPN use on untrusted networks.
- Source published
- First seen by Cybersecurity Tracker