Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

TeamPCP Traced Back to 2020 Cryptojacking Operation

August 6, 2026

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

August 6, 2026

Toolkit Hidden Inside Oracle Database Evades Endpoint Tools

August 6, 2026
Facebook X (Twitter) Instagram
Thursday, August 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
News

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Team-CWDBy Team-CWDAugust 6, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.

Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as APT29 and Cozy Bear. The U.S. and U.K. governments attribute the broader actor to Russia’s Foreign Intelligence Service (SVR).

On the compromised networks ReliaQuest investigated, the captive portal gateway also served as the DNS resolver assigned to connected devices. Administrative control of that gateway let the attackers forge Domain Name System (DNS) answers and redirect the resulting traffic. They could then redirect a laptop’s automatic connectivity check to a fake browser or operating system update.

Some pages use ClickFix instructions that tell victims to open a terminal or another Windows utility and run an attacker-supplied command. The gateway controls where the user is sent, but it does not silently infect the endpoint. The victim still has to download or execute the payload.

Microsoft has observed the traffic manipulation since early May across hospitality networks in several countries, but it has not named a hotel, venue, or captive portal vendor. ReliaQuest recommends an always-on, full-tunnel virtual private network (VPN), which sends DNS queries through corporate resolvers before the venue’s gateway can answer them.

Researchers advise travelers to use private connections and reject software updates, certificates, browser updates, troubleshooting tools, or security utilities offered through captive portals.

Since July 16, some CaptiveCrunch landing pages have redirected guests into Microsoft’s device code authentication flow. Entering the attacker-supplied code on Microsoft’s legitimate sign-in page can grant the attacker-controlled session multi-factor authentication (MFA)-satisfied access. Microsoft recommends blocking the flow through Conditional Access wherever it is not needed.

CornFlake, a Go-based implant, copies itself to %APPDATA%svchost32svchost32.exe and registers the svchost32 service under the display name Cloud Sync Service. A fake progress window holds the victim’s attention while this happens.

Microsoft’s analysis says the implant can take idle-triggered screenshots, record clipboard contents with the active window title, steal browser cookies and saved passwords, including cookies protected by Chrome App-Bound Encryption, scan removable media, and open a remote shell. It also uses a Registry Run key and a scheduled task, while a watchdog restores any persistence mechanism defenders remove.

Researchers also identified ChocoShell, an in-memory PowerShell stealer. It collects Microsoft 365 and Azure Active Directory access and refresh tokens, plus Web Account Manager (WAM) tokens, from .tbres files in the Token Broker cache. The stolen tokens can enable session replay without a browser cookie.

The reports document active redirection and malware delivery, but do not quantify their reach or conversion. Without counts of successful executions, device-code approvals, or stolen accounts, the public record does not show how often a redirect became a compromise.

Microsoft found common equipment and management systems across the affected networks, which it says could reflect access to shared services within portions of the captive portal ecosystem. If so, the compromises may not have been isolated to individual venues. Microsoft has not named any affected provider.

ReliaQuest documented the same Microsoft-impersonating domains and overlapping infrastructure eight days earlier. It said the tradecraft resembled APT28, the GRU unit also called Fancy Bear and Forest Blizzard, but stopped short of attribution because the assessment rests on TTP overlap rather than direct technical linkage.

Microsoft acknowledges the similarity to the Forest Blizzard router hijacking it disclosed in April while attributing CaptiveCrunch to Storm-2945.

The U.K. National Cyber Security Centre and its international partners assess that APT29 is almost certainly part of Russia’s Foreign Intelligence Service. That government attribution covers the broader APT29 group. The CaptiveCrunch-to-Storm-2945 link remains Microsoft’s assessment. No separate public technical report has independently corroborated it.

The initial compromise vector remains under investigation. ReliaQuest assesses with low-to-medium confidence that a combination of exposed management interfaces and weak or reused administrator credentials may have provided access, but said visibility constraints prevented confirmation.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleToolkit Hidden Inside Oracle Database Evades Endpoint Tools
Next Article TeamPCP Traced Back to 2020 Cryptojacking Operation
Team-CWD
  • Website

Related Posts

News

TeamPCP Traced Back to 2020 Cryptojacking Operation

August 6, 2026
News

Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident

August 6, 2026
News

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

August 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Top IRS scams to look out for in 2026

February 10, 2026

Find your weak spots before attackers do

November 21, 2025

Mobile app permissions (still) matter more than you may think

February 27, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.