Compromised Hotel Wi-Fi Used to Push Fake Browser Updates Delivering CornFlake RAT
Microsoft has reported a campaign, tracked as CaptiveCrunch, in which attackers hijacked hotel Wi-Fi networks to serve fake browser update prompts. Victims who accept the update are infected with CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. Microsoft attributes the activity to Storm-2945, which it assesses to be an operational sub-cluster of Midnight Blizzard.
Why It Matters
This is a fake-update ("FakeUpdate"/ClickFix-style) social engineering technique delivered via a network-level compromise rather than a malicious website alone — hijacking the captive portal or traffic of hotel Wi-Fi gives the attacker a trusted-looking vector to reach travelers, including business and government personnel who may be higher-value surveillance targets. The CornFlake payload's capabilities (webcam, mic, keystroke capture) point to an intelligence-gathering/surveillance objective consistent with the alleged Midnight Blizzard lineage, rather than opportunistic financial crime. Anyone connecting to hotel or other public/semi-trusted Wi-Fi is potentially exposed.
What Defenders Should Watch For
- Fake browser/software update prompts appearing immediately after connecting to hotel or public Wi-Fi captive portals, especially ones that redirect to unexpected domains before or during the captive portal flow.
- Endpoint alerts for downloaded/executed files masquerading as browser updaters, particularly those spawning processes with webcam, microphone, or keylogging-related API calls.
- Network monitoring for anomalous DNS/TLS traffic originating from devices that recently joined hotel or travel-related Wi-Fi networks.
- User education for traveling staff: treat unsolicited browser/software update prompts on hotel or public networks with suspicion, and prefer updates delivered through the OS/browser's built-in update mechanism rather than a web pop-up.
- Where feasible, require VPN use on untrusted networks and restrict local admin rights to reduce the impact of a successful drive-by install.
This report is still developing and details on indicators of compromise, full attribution confidence, and scope are limited at this time. For the original reporting, see The Hacker News.