Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

The Hacker News by The Hacker News
August 1, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalAug 01, 2026Malware / Cyber Espionage

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.

Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as APT29 and Cozy Bear. The U.S. and U.K. governments attribute the broader actor to Russia’s Foreign Intelligence Service (SVR).

On the compromised networks ReliaQuest investigated, the captive portal gateway also served as the DNS resolver assigned to connected devices. Administrative control of that gateway let the attackers forge Domain Name System (DNS) answers and redirect the resulting traffic. They could then redirect a laptop’s automatic connectivity check to a fake browser or operating system update.

Some pages use ClickFix instructions that tell victims to open a terminal or another Windows utility and run an attacker-supplied command. The gateway controls where the user is sent, but it does not silently infect the endpoint. The victim still has to download or execute the payload.

Microsoft has observed the traffic manipulation since early May across hospitality networks in several countries, but it has not named a hotel, venue, or captive portal vendor. ReliaQuest recommends an always-on, full-tunnel virtual private network (VPN), which sends DNS queries through corporate resolvers before the venue’s gateway can answer them.

Researchers advise travelers to use private connections and reject software updates, certificates, browser updates, troubleshooting tools, or security utilities offered through captive portals.

Since July 16, some CaptiveCrunch landing pages have redirected guests into Microsoft’s device code authentication flow. Entering the attacker-supplied code on Microsoft’s legitimate sign-in page can grant the attacker-controlled session multi-factor authentication (MFA)-satisfied access. Microsoft recommends blocking the flow through Conditional Access wherever it is not needed.

CornFlake, a Go-based implant, copies itself to %APPDATA%svchost32svchost32.exe and registers the svchost32 service under the display name Cloud Sync Service. A fake progress window holds the victim’s attention while this happens.

Microsoft’s analysis says the implant can take idle-triggered screenshots, record clipboard contents with the active window title, steal browser cookies and saved passwords, including cookies protected by Chrome App-Bound Encryption, scan removable media, and open a remote shell. It also uses a Registry Run key and a scheduled task, while a watchdog restores any persistence mechanism defenders remove.

Researchers also identified ChocoShell, an in-memory PowerShell stealer. It collects Microsoft 365 and Azure Active Directory access and refresh tokens, plus Web Account Manager (WAM) tokens, from .tbres files in the Token Broker cache. The stolen tokens can enable session replay without a browser cookie.

The reports document active redirection and malware delivery, but do not quantify their reach or conversion. Without counts of successful executions, device-code approvals, or stolen accounts, the public record does not show how often a redirect became a compromise.

Microsoft found common equipment and management systems across the affected networks, which it says could reflect access to shared services within portions of the captive portal ecosystem. If so, the compromises may not have been isolated to individual venues. Microsoft has not named any affected provider.

ReliaQuest documented the same Microsoft-impersonating domains and overlapping infrastructure eight days earlier. It said the tradecraft resembled APT28, the GRU unit also called Fancy Bear and Forest Blizzard, but stopped short of attribution because the assessment rests on TTP overlap rather than direct technical linkage.

Microsoft acknowledges the similarity to the Forest Blizzard router hijacking it disclosed in April while attributing CaptiveCrunch to Storm-2945.

The U.K. National Cyber Security Centre and its international partners assess that APT29 is almost certainly part of Russia’s Foreign Intelligence Service. That government attribution covers the broader APT29 group. The CaptiveCrunch-to-Storm-2945 link remains Microsoft’s assessment. No separate public technical report has independently corroborated it.

The initial compromise vector remains under investigation. ReliaQuest assesses with low-to-medium confidence that a combination of exposed management interfaces and weak or reused administrator credentials may have provided access, but said visibility constraints prevented confirmation.



Source link

The Hacker News

The Hacker News

Next Post
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Recommended.

L’ICANN85 à Mumbai : Renforcer l’internet unique et interopérable pour tous

L’ICANN85 à Mumbai : Renforcer l’internet unique et interopérable pour tous

February 6, 2026
Spitzer Autoworld Launches Exclusive Spitzer VIP Program Across Ohio Dealerships

Spitzer Autoworld Launches Exclusive Spitzer VIP Program Across Ohio Dealerships

August 2, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026
Cloud revenues up 35% YoY in a hot market that’s accelerating | Computer Weekly

Cloud revenues up 35% YoY in a hot market that’s accelerating | Computer Weekly

April 30, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio