A recent report from Microsoft reveals a significant cybersecurity threat involving hotel Wi-Fi networks, which have been hijacked to distribute fake browser updates. These updates are used to deliver CornFlake, a remote access trojan (RAT) capable of surveillance activities like capturing webcam images, microphone audio, and keystrokes.
Operation CaptiveCrunch and Its Origins
The operation, known as CaptiveCrunch, is linked to Storm-2945, a group identified as part of the wider Midnight Blizzard network. This group, also recognized as APT29 or Cozy Bear, is attributed to the Russian Foreign Intelligence Service (SVR) by U.S. and U.K. authorities.
ReliaQuest’s investigation into affected networks found that attackers manipulated DNS settings through administrative access to captive portal gateways. This allowed them to redirect traffic, leading users to download malicious updates disguised as legitimate browser or OS updates.
Methods of Malware Distribution
The attackers employed ClickFix techniques to guide users into executing malicious commands, although user interaction is required to activate the payload. Microsoft’s findings indicate these manipulations have been ongoing since May, targeting hospitality networks globally.
ReliaQuest advises travelers to use full-tunnel VPNs to route DNS queries through secure corporate resolvers, preventing the venue’s gateway from altering them. They also recommend rejecting any updates or security prompts offered via captive portals.
Technical Details and Defensive Measures
Since mid-July, some phishing pages have redirected users to Microsoft’s device code authentication flow, potentially allowing unauthorized multi-factor authentication (MFA) access. Microsoft advises organizations to restrict this flow through Conditional Access settings.
The CornFlake trojan, written in Go, installs itself in the %APPDATA% directory, masquerading as a legitimate service, while it secretly performs a variety of malicious tasks such as stealing browser cookies and passwords.
Additionally, an in-memory PowerShell stealer named ChocoShell has been found extracting tokens for Microsoft 365 and Azure Active Directory, facilitating session replays without browser cookies.
Wider Implications and Ongoing Investigations
The scope of the operation remains unclear, with no public data on successful compromises. Microsoft suggests that shared services within the captive portal ecosystem might have been exploited, hinting at a broader impact beyond individual hotels.
ReliaQuest identified similarities with previous APT28 operations, though they refrain from definitive attribution based solely on common tactics, techniques, and procedures.
As investigations continue, ReliaQuest speculates that weak administrative credentials might have facilitated initial access, although confirmation remains elusive due to limited visibility.
