Skip to content
feed: live
>_ 0dayNews
threat intel
● Breaking

Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT

Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.

Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 2 min read

Russian state-sponsored actor. Hotel Wi-Fi as the attack surface. Surveillance RAT on the far end.

Microsoft published a report on August 1, 2026 disclosing CaptiveCrunch, an operation attributed to Storm-2945 — assessed by Microsoft as an operational sub-cluster of Midnight Blizzard (also tracked as APT29 and Cozy Bear). The operation hijacks hotel Wi-Fi infrastructure and serves fake browser update prompts to connected guests. Accepting the prompt delivers CornFlake, a remote access trojan.

Confidence on attribution: confirmed per Microsoft’s published report.

What CornFlake does

CornFlake is a RAT. Confirmed capabilities per Microsoft’s disclosure:

  • Webcam image capture
  • Microphone audio recording
  • Keystroke logging

Confidence on the above: confirmed. Whether CornFlake stages additional payloads, beacons to a command-and-control server, or exfiltrates files beyond what’s listed is not detailed in the public report. Treat the disclosed capability set as a minimum, not a ceiling.

The delivery chain

Per Microsoft’s report:

  1. A guest connects to hotel Wi-Fi. The network has been hijacked — the specific compromise method is not disclosed in the public report.
  2. The compromised network delivers a fake browser update prompt to the guest’s device.
  3. The guest interacts with the prompt. CornFlake is installed.
  4. CornFlake begins collection: webcam, audio, keystrokes.

No CVE is associated with this campaign. Delivery depends entirely on user interaction with the fake update prompt — there is no patch that closes this vector.

Context: hotel networks as an APT vector

Hotel Wi-Fi is not a new attack surface for advanced persistent threats. We previously covered DNS hijacking over hotel networks — a separate technique redirecting guests to fake Microsoft 365 login pages to harvest credentials. No overlap between that campaign and CaptiveCrunch has been reported in public materials.

CaptiveCrunch’s objective differs. A credential-phishing page produces one-time access. A surveillance RAT produces persistent device access and real-time collection — webcam, audio, keystrokes — for the duration it remains installed.

Analysis: Business travelers are high-value SVR targets. A compromised device carries corporate access, VPN credentials, session tokens, and behavioral patterns back into enterprise environments. Attribution to Midnight Blizzard — the SVR cyber arm with a documented history of targeting diplomatic, government, and strategic research organizations — is consistent with that collection priority. Russia-linked surveillance operations against travel and transport infrastructure have been publicly documented by Western intelligence services.

Label: Analysis. Objective attribution beyond what Microsoft has stated is not confirmed here.

What to do

No patch applies. Mitigate exposure:

  • VPN before anything else on hotel Wi-Fi. Connect a VPN tunnel before any browser activity. The captive portal authentication window requires an unencrypted initial connection — keep that window as narrow as possible, then tunnel everything.
  • Reject browser update prompts on unfamiliar networks. Browser updates are delivered through the browser itself or the operating system — not through network redirects or captive portal pages. Any such prompt on hotel Wi-Fi should be treated as hostile.
  • Disable auto-connect to remembered hotel networks. Verify the network manually at each stay.
  • If an unexpected browser update prompt appeared on hotel Wi-Fi recently: treat the device as potentially compromised. Isolate it, investigate, and rotate all credentials from a separate clean device before reconnecting to corporate systems.

This operation is active per Microsoft’s reporting as of August 1, 2026.

Source: The Hacker News — Microsoft threat intelligence report, published August 1, 2026.

Found this useful? Share it.