live markets
S&P 5006,389.45▲ 0.42%NASDAQ21,102.30▲ 0.61%DOW44,812.10▼ 0.18%GOLD3,412.80▲ 0.35%WTI CRUDE68.42▼ 1.12%BRENT72.18▼ 0.94%EUR/USD1.0842▲ 0.08%GBP/USD1.3391▼ 0.05%JPY/USD0.0068▲ 0.11%NAT GAS3.12▲ 0.74%
pulseofnations.
Sat, Aug 1 2026 — 10:29 UTC telegram ↗ Join the wire

Hotel Wi-Fi Hacks Push Fake Updates With Spy Malware

Microsoft says a Russia-linked group hijacked hotel Wi-Fi to push fake browser updates, delivering CornFlake spyware that steals credentials.

Microsoft has revealed that a fake browser update served over hijacked hotel Wi-Fi networks has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio and keystrokes from travelers.

Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945, which Microsoft assesses to be an operational sub-cluster of Midnight Blizzard, also known as APT29 and Cozy Bear. The U.S. and U.K. governments attribute the broader actor to Russia’s Foreign Intelligence Service (SVR).

On the compromised networks investigated by ReliaQuest, the captive portal gateway also served as the DNS resolver assigned to connected devices. Administrative control of that gateway let the attackers forge DNS answers and redirect traffic, steering a laptop’s automatic connectivity check to a fake browser or operating system update. Some pages use ClickFix instructions that tell victims to open a terminal or another Windows utility and run an attacker-supplied command. The gateway controls where the user is sent, but it does not silently infect the endpoint; the victim still has to download or execute the payload.

Microsoft has observed the traffic manipulation since early May across hospitality networks in several countries, though it has not named a hotel, venue or captive portal vendor. Since July 16, some CaptiveCrunch landing pages have redirected guests into Microsoft’s device code authentication flow; entering the attacker-supplied code on Microsoft’s legitimate sign-in page can grant the attacker-controlled session multi-factor authentication (MFA)-satisfied access. Microsoft recommends blocking the flow through Conditional Access wherever it is not needed.

CornFlake, a Go-based implant, copies itself to %APPDATA%\svchost32\svchost32.exe and registers a service under the display name Cloud Sync Service. Microsoft’s analysis says the implant can take idle-triggered screenshots, record clipboard contents with the active window title, steal browser cookies and saved passwords (including cookies protected by Chrome App-Bound Encryption), scan removable media and open a remote shell. A watchdog restores any persistence mechanism that defenders remove.

Researchers also identified ChocoShell, an in-memory PowerShell stealer that collects Microsoft 365 and Azure Active Directory access and refresh tokens, plus Web Account Manager (WAM) tokens from the Token Broker cache. The stolen tokens can enable session replay without a browser cookie, letting attackers maintain access even after credentials are rotated.

ReliaQuest documented the same Microsoft-impersonating domains and overlapping infrastructure eight days earlier and said the tradecraft resembled APT28, the GRU unit also called Fancy Bear and Forest Blizzard, though it stopped short of attribution. Microsoft acknowledges the similarity to the Forest Blizzard router hijacking it disclosed in April while attributing CaptiveCrunch to Storm-2945. The U.K. National Cyber Security Centre and its international partners assess that APT29 is almost certainly part of Russia’s Foreign Intelligence Service.

For travelers, researchers advise using an always-on, full-tunnel virtual private network (VPN), which sends DNS queries through corporate resolvers before the venue’s gateway can answer them, and rejecting software updates, certificates, browser updates, troubleshooting tools or security utilities offered through captive portals. The reports document active redirection and malware delivery but do not quantify how often a redirect turned into a full compromise.

Sources: The Hacker News, Microsoft Security Blog, ReliaQuest Threat Spotlight

Author: Technology Desk

React to this dispatch
Share this dispatch Telegram X WhatsApp

discussion

Join the discussion

Your email address will not be published. Required fields are marked *