Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hotel Wi-Fi Exploited to Distribute Surveillance Trojan

Hotel Wi-Fi Exploited to Distribute Surveillance Trojan

Posted on August 1, 2026 By CWS

A recent report from Microsoft reveals a significant cybersecurity threat involving hotel Wi-Fi networks, which have been hijacked to distribute fake browser updates. These updates are used to deliver CornFlake, a remote access trojan (RAT) capable of surveillance activities like capturing webcam images, microphone audio, and keystrokes.

Operation CaptiveCrunch and Its Origins

The operation, known as CaptiveCrunch, is linked to Storm-2945, a group identified as part of the wider Midnight Blizzard network. This group, also recognized as APT29 or Cozy Bear, is attributed to the Russian Foreign Intelligence Service (SVR) by U.S. and U.K. authorities.

ReliaQuest’s investigation into affected networks found that attackers manipulated DNS settings through administrative access to captive portal gateways. This allowed them to redirect traffic, leading users to download malicious updates disguised as legitimate browser or OS updates.

Methods of Malware Distribution

The attackers employed ClickFix techniques to guide users into executing malicious commands, although user interaction is required to activate the payload. Microsoft’s findings indicate these manipulations have been ongoing since May, targeting hospitality networks globally.

ReliaQuest advises travelers to use full-tunnel VPNs to route DNS queries through secure corporate resolvers, preventing the venue’s gateway from altering them. They also recommend rejecting any updates or security prompts offered via captive portals.

Technical Details and Defensive Measures

Since mid-July, some phishing pages have redirected users to Microsoft’s device code authentication flow, potentially allowing unauthorized multi-factor authentication (MFA) access. Microsoft advises organizations to restrict this flow through Conditional Access settings.

The CornFlake trojan, written in Go, installs itself in the %APPDATA% directory, masquerading as a legitimate service, while it secretly performs a variety of malicious tasks such as stealing browser cookies and passwords.

Additionally, an in-memory PowerShell stealer named ChocoShell has been found extracting tokens for Microsoft 365 and Azure Active Directory, facilitating session replays without browser cookies.

Wider Implications and Ongoing Investigations

The scope of the operation remains unclear, with no public data on successful compromises. Microsoft suggests that shared services within the captive portal ecosystem might have been exploited, hinting at a broader impact beyond individual hotels.

ReliaQuest identified similarities with previous APT28 operations, though they refrain from definitive attribution based solely on common tactics, techniques, and procedures.

As investigations continue, ReliaQuest speculates that weak administrative credentials might have facilitated initial access, although confirmation remains elusive due to limited visibility.

The Hacker News Tags:APT29, captive portal, CornFlake, cyber espionage, Cybersecurity, fake updates, hotel Wi-Fi, Malware, Microsoft, network security, RAT, ReliaQuest, remote access trojan, safety tips, Storm-2945

Post navigation

Previous Post: Critical Adobe Campaign Flaw Poses Code Execution Risk
Next Post: Hackers Exploit Adform Script to Alter Crypto Wallets

Related Posts

Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware The Hacker News
 Google Sues China-Based Hackers Behind  Billion Lighthouse Phishing Platform  Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform The Hacker News
U.S. Targets VPN and Cryptor Seller for Ransomware Aid U.S. Targets VPN and Cryptor Seller for Ransomware Aid The Hacker News
Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and Proxyware Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and Proxyware The Hacker News
Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks The Hacker News
RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Balance Theory Secures $19M for Cybersecurity Investment Platform
  • Critical Ruby on Rails Vulnerability Patched
  • Hackers Exploit Adform Script to Alter Crypto Wallets
  • Hotel Wi-Fi Exploited to Distribute Surveillance Trojan
  • Critical Adobe Campaign Flaw Poses Code Execution Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Balance Theory Secures $19M for Cybersecurity Investment Platform
  • Critical Ruby on Rails Vulnerability Patched
  • Hackers Exploit Adform Script to Alter Crypto Wallets
  • Hotel Wi-Fi Exploited to Distribute Surveillance Trojan
  • Critical Adobe Campaign Flaw Poses Code Execution Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark