Fake Wi-Fi Updates Deploy CornFlake RAT


Hackers hijack hospitality Wi-Fi portals to deliver CornFlake RAT, steal Microsoft 365 tokens and target travelers.

Travelers connecting to public Wi-Fi at hotels and other hospitality venues could be at risk from a new cyberattack that disguises malware as legitimate software updates, according to new research from Microsoft.

The campaign, which Microsoft tracks as CaptiveCrunch, has been active since at least early May 2026. Researchers attribute the activity to Storm-2945, a subgroup that Microsoft believes is linked to Midnight Blizzard, also known as APT29 or Cozy Bear. The broader APT29 hacking group has long been attributed by the United States and the United Kingdom to Russia’s Foreign Intelligence Service (SVR).

According to Microsoft and cybersecurity company ReliaQuest, the attackers first gained control of Wi-Fi captive portal infrastructure used by hospitality venues. Because the compromised gateway also handled DNS requests, the attackers were able to manipulate internet traffic and redirect victims away from legitimate pages.

Rather than seeing the usual internet connectivity check, victims were presented with convincing browser or operating system update pages. Some of these fake update screens used the ClickFix social engineering technique, instructing users to open Windows Terminal or another built-in utility and run commands provided by the attackers. The attack still relied on user interaction, however the malware was only installed if the victim downloaded or executed the supplied payload.

Microsoft also observed a change in the campaign beginning on July 16, when some of the fake pages started redirecting users to Microsoft’s legitimate device code authentication page. Victims who entered an attacker-supplied code could unknowingly authorize an attacker-controlled session that had already satisfied multi-factor authentication (MFA) requirements. To reduce this risk, Microsoft recommends disabling device code authentication through Conditional Access wherever it is not required.

The primary payload delivered in the campaign is CornFlake, a remote access trojan (RAT) written in the Go programming language. After installation, the malware copies itself into the victim’s %APPDATA% folder, registers itself as a Windows service named Cloud Sync Service, and displays a fake progress window while it quietly installs in the background.

Once active, CornFlake gives attackers extensive control over an infected system. Microsoft said the malware can capture webcam images, record microphone audio, log keystrokes, take screenshots when the computer is idle, monitor clipboard contents together with the active window title, steal browser cookies and saved passwords including cookies protected by Chrome App-Bound Encryption scan removable storage devices, and open a remote shell on the compromised device. It also uses multiple persistence techniques, including Registry Run keys, scheduled tasks, and a watchdog process that automatically restores those mechanisms if they are removed.

Researchers also identified a second tool called ChocoShell, a memory-resident PowerShell stealer designed to extract authentication tokens from Microsoft 365, Microsoft Entra ID, and Web Account Manager (WAM). Unlike traditional cookie theft, these stolen tokens can allow attackers to hijack authenticated sessions without needing access to a victim’s browser cookies.

While Microsoft and ReliaQuest confirmed that attackers were actively redirecting users and delivering malware, neither company disclosed how many people had ultimately been compromised. Microsoft also declined to identify any affected hotels, hospitality providers, captive portal vendors, or equipment manufacturers.

Investigators did find common networking equipment and management systems across several affected hospitality networks, raising the possibility that the attackers gained access to shared services used by multiple venues rather than compromising each location individually. Even so, Microsoft said the initial point of entry is still being investigated.

ReliaQuest assessed with low-to-medium confidence that exposed management interfaces or weak and reused administrator credentials may have allowed the attackers to gain access, although the company said there is not yet enough evidence to confirm the exact intrusion method.

Microsoft also noted similarities between CaptiveCrunch and the Forest Blizzard (APT28) router hijacking campaign disclosed earlier this year. Despite those similarities, the company continues to attribute the activity to Storm-2945. ReliaQuest reached a similar conclusion, observing overlapping infrastructure but stopping short of making its own attribution because the similarities were based on tactics and infrastructure rather than direct technical evidence.

The campaign serves as another reminder that public Wi-Fi networks can present security risks, particularly when they require users to pass through captive portals. Microsoft advises travelers to use a trusted VPN whenever possible, avoid installing software offered through public Wi-Fi login pages, and download updates only from official sources.

Source : The Hacker News

Related articles :


Reports are sourced from official documents, law-enforcement updates, and credible investigations.

Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.