A recently discovered campaign, tracked as CaptiveCrunch, exploits compromised hotel Wi-Fi networks to distribute a remote access trojan (RAT) known as CornFlake, which can record keystrokes, audio, and webcam footage. This malware is delivered through fake browser updates, allowing attackers to gain extensive control over infected devices. The operation is attributed to Storm-2945, a subgroup of the Midnight Blizzard threat actor. Microsoft has identified this campaign, highlighting the shift from traditional cybercrime to state-aligned activities, which alters the threat landscape and requires a distinct response strategy1. The use of hijacked hotel Wi-Fi networks as an attack vector underscores the importance of verifying the security of public networks. This campaign's attribution to a state-aligned group signifies a change in the threat model, making it crucial for organizations to reassess their security posture and adapt to the evolving geopolitical landscape.