Microsoft has detailed a campaign in which attackers hijack hotel Wi-Fi networks to serve fake browser update prompts that install a remote access trojan called CornFlake. The malware is capable of capturing webcam images, recording microphone audio, and logging keystrokes, giving operators a broad surveillance capability over infected devices.
Microsoft researchers track the operation as CaptiveCrunch and attribute it to a threat actor cluster designated Storm-2945. According to the report, Storm-2945 is assessed to be an operational sub-cluster of Midnight Blizzard, the Russian state-linked group also known by other industry aliases and previously associated with espionage-focused intrusions.
How the attack works
The campaign relies on hijacking hotel Wi-Fi infrastructure, likely including captive portal pages that guests interact with when connecting to network access. Instead of a legitimate login or terms-of-service page, victims are presented with a fake browser update notification. Users who accept the prompt unknowingly install CornFlake, giving the attackers a foothold on the device.
Because the lure exploits a trusted, routine interaction (connecting to hotel guest Wi-Fi), it can bypass the skepticism travelers might otherwise apply to unsolicited software prompts encountered elsewhere.
Why it matters
The targeting of hotel networks suggests a focus on travelers, a group that often includes executives, diplomats, journalists, and other individuals of intelligence interest. Combined with CornFlake’s surveillance features, the campaign points to an espionage-oriented objective consistent with Midnight Blizzard’s historical operations.
- Vector: Compromised hotel Wi-Fi networks and captive portals
- Lure: Fake browser update prompts
- Payload: CornFlake RAT with webcam, microphone, and keystroke capture
- Attribution: Storm-2945, assessed as a Midnight Blizzard sub-cluster
Security teams supporting frequent travelers should treat unsolicited browser update prompts on public or hotel Wi-Fi with heightened suspicion, verify updates only through official application channels, and consider requiring VPN use on untrusted networks to reduce exposure to captive portal manipulation.
