← Blog · · df00tech

Compromised Hotel Wi-Fi Used to Push Fake Browser Updates Delivering CornFlake RAT

security-news campaign

Microsoft has reported a campaign, tracked as CaptiveCrunch, in which attackers hijacked hotel Wi-Fi networks to serve fake browser update prompts. Victims who accept the update are infected with CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. Microsoft attributes the activity to Storm-2945, which it assesses to be an operational sub-cluster of Midnight Blizzard.

Why It Matters

This is a fake-update ("FakeUpdate"/ClickFix-style) social engineering technique delivered via a network-level compromise rather than a malicious website alone — hijacking the captive portal or traffic of hotel Wi-Fi gives the attacker a trusted-looking vector to reach travelers, including business and government personnel who may be higher-value surveillance targets. The CornFlake payload's capabilities (webcam, mic, keystroke capture) point to an intelligence-gathering/surveillance objective consistent with the alleged Midnight Blizzard lineage, rather than opportunistic financial crime. Anyone connecting to hotel or other public/semi-trusted Wi-Fi is potentially exposed.

What Defenders Should Watch For

  • Fake browser/software update prompts appearing immediately after connecting to hotel or public Wi-Fi captive portals, especially ones that redirect to unexpected domains before or during the captive portal flow.
  • Endpoint alerts for downloaded/executed files masquerading as browser updaters, particularly those spawning processes with webcam, microphone, or keylogging-related API calls.
  • Network monitoring for anomalous DNS/TLS traffic originating from devices that recently joined hotel or travel-related Wi-Fi networks.
  • User education for traveling staff: treat unsolicited browser/software update prompts on hotel or public networks with suspicion, and prefer updates delivered through the OS/browser's built-in update mechanism rather than a web pop-up.
  • Where feasible, require VPN use on untrusted networks and restrict local admin rights to reduce the impact of a successful drive-by install.

This report is still developing and details on indicators of compromise, full attribution confidence, and scope are limited at this time. For the original reporting, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.