A recently discovered campaign, tracked as CaptiveCrunch, exploits compromised hotel Wi-Fi networks to distribute a remote access trojan (RAT) known as CornFlake, which can record keystrokes, audio, and webcam footage. This malware is delivered through fake browser updates, allowing attackers to gain extensive control over infected devices. The operation is attributed to Storm-2945, a subgroup of the Midnight Blizzard threat actor. Microsoft has identified this campaign, highlighting the shift from traditional cybercrime to state-aligned activities, which alters the threat landscape and requires a distinct response strategy1. The use of hijacked hotel Wi-Fi networks as an attack vector underscores the importance of verifying the security of public networks. This campaign's attribution to a state-aligned group signifies a change in the threat model, making it crucial for organizations to reassess their security posture and adapt to the evolving geopolitical landscape.
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
⚡ High Priority
Why This Matters
State-aligned activity involving Microsoft shifts the threat model from criminal to geopolitical — different playbook required.
References
- The Hacker News. (2026, August 1). Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware. *The Hacker News*. https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html
Original Source
The Hacker News
Read original →