Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hotel Wi-Fi Exploited to Distribute Surveillance Trojan

Hotel Wi-Fi Exploited to Distribute Surveillance Trojan

Posted on August 1, 2026 By CWS

A recent report from Microsoft reveals a significant cybersecurity threat involving hotel Wi-Fi networks, which have been hijacked to distribute fake browser updates. These updates are used to deliver CornFlake, a remote access trojan (RAT) capable of surveillance activities like capturing webcam images, microphone audio, and keystrokes.

Operation CaptiveCrunch and Its Origins

The operation, known as CaptiveCrunch, is linked to Storm-2945, a group identified as part of the wider Midnight Blizzard network. This group, also recognized as APT29 or Cozy Bear, is attributed to the Russian Foreign Intelligence Service (SVR) by U.S. and U.K. authorities.

ReliaQuest’s investigation into affected networks found that attackers manipulated DNS settings through administrative access to captive portal gateways. This allowed them to redirect traffic, leading users to download malicious updates disguised as legitimate browser or OS updates.

Methods of Malware Distribution

The attackers employed ClickFix techniques to guide users into executing malicious commands, although user interaction is required to activate the payload. Microsoft’s findings indicate these manipulations have been ongoing since May, targeting hospitality networks globally.

ReliaQuest advises travelers to use full-tunnel VPNs to route DNS queries through secure corporate resolvers, preventing the venue’s gateway from altering them. They also recommend rejecting any updates or security prompts offered via captive portals.

Technical Details and Defensive Measures

Since mid-July, some phishing pages have redirected users to Microsoft’s device code authentication flow, potentially allowing unauthorized multi-factor authentication (MFA) access. Microsoft advises organizations to restrict this flow through Conditional Access settings.

The CornFlake trojan, written in Go, installs itself in the %APPDATA% directory, masquerading as a legitimate service, while it secretly performs a variety of malicious tasks such as stealing browser cookies and passwords.

Additionally, an in-memory PowerShell stealer named ChocoShell has been found extracting tokens for Microsoft 365 and Azure Active Directory, facilitating session replays without browser cookies.

Wider Implications and Ongoing Investigations

The scope of the operation remains unclear, with no public data on successful compromises. Microsoft suggests that shared services within the captive portal ecosystem might have been exploited, hinting at a broader impact beyond individual hotels.

ReliaQuest identified similarities with previous APT28 operations, though they refrain from definitive attribution based solely on common tactics, techniques, and procedures.

As investigations continue, ReliaQuest speculates that weak administrative credentials might have facilitated initial access, although confirmation remains elusive due to limited visibility.

The Hacker News Tags:APT29, captive portal, CornFlake, cyber espionage, Cybersecurity, fake updates, hotel Wi-Fi, Malware, Microsoft, network security, RAT, ReliaQuest, remote access trojan, safety tips, Storm-2945

Post navigation

Previous Post: Critical Adobe Campaign Flaw Poses Code Execution Risk
Next Post: Hackers Exploit Adform Script to Alter Crypto Wallets

Related Posts

Context Is the Key to Effective Incident Response Context Is the Key to Effective Incident Response The Hacker News
New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers The Hacker News
Click Studios Patches Passwordstate Authentication Bypass Vulnerability in Emergency Access Page Click Studios Patches Passwordstate Authentication Bypass Vulnerability in Emergency Access Page The Hacker News
Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas The Hacker News
Critical Security Threats and Global Cyber Developments Critical Security Threats and Global Cyber Developments The Hacker News
Microsoft 365 Android Apps Vulnerability Allows Token Theft Microsoft 365 Android Apps Vulnerability Allows Token Theft The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Ruby on Rails Vulnerability Patched
  • Hackers Exploit Adform Script to Alter Crypto Wallets
  • Hotel Wi-Fi Exploited to Distribute Surveillance Trojan
  • Critical Adobe Campaign Flaw Poses Code Execution Risk
  • Arch Linux Halts AUR Adoptions Amid Security Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Ruby on Rails Vulnerability Patched
  • Hackers Exploit Adform Script to Alter Crypto Wallets
  • Hotel Wi-Fi Exploited to Distribute Surveillance Trojan
  • Critical Adobe Campaign Flaw Poses Code Execution Risk
  • Arch Linux Halts AUR Adoptions Amid Security Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark