Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT
Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.
Russian state-sponsored actor. Hotel Wi-Fi as the attack surface. Surveillance RAT on the far end.
Microsoft published a report on August 1, 2026 disclosing CaptiveCrunch, an operation attributed to Storm-2945 — assessed by Microsoft as an operational sub-cluster of Midnight Blizzard (also tracked as APT29 and Cozy Bear). The operation hijacks hotel Wi-Fi infrastructure and serves fake browser update prompts to connected guests. Accepting the prompt delivers CornFlake, a remote access trojan.
Confidence on attribution: confirmed per Microsoft’s published report.
What CornFlake does
CornFlake is a RAT. Confirmed capabilities per Microsoft’s disclosure:
- Webcam image capture
- Microphone audio recording
- Keystroke logging
Confidence on the above: confirmed. Whether CornFlake stages additional payloads, beacons to a command-and-control server, or exfiltrates files beyond what’s listed is not detailed in the public report. Treat the disclosed capability set as a minimum, not a ceiling.
The delivery chain
Per Microsoft’s report:
- A guest connects to hotel Wi-Fi. The network has been hijacked — the specific compromise method is not disclosed in the public report.
- The compromised network delivers a fake browser update prompt to the guest’s device.
- The guest interacts with the prompt. CornFlake is installed.
- CornFlake begins collection: webcam, audio, keystrokes.
No CVE is associated with this campaign. Delivery depends entirely on user interaction with the fake update prompt — there is no patch that closes this vector.
Context: hotel networks as an APT vector
Hotel Wi-Fi is not a new attack surface for advanced persistent threats. We previously covered DNS hijacking over hotel networks — a separate technique redirecting guests to fake Microsoft 365 login pages to harvest credentials. No overlap between that campaign and CaptiveCrunch has been reported in public materials.
CaptiveCrunch’s objective differs. A credential-phishing page produces one-time access. A surveillance RAT produces persistent device access and real-time collection — webcam, audio, keystrokes — for the duration it remains installed.
Analysis: Business travelers are high-value SVR targets. A compromised device carries corporate access, VPN credentials, session tokens, and behavioral patterns back into enterprise environments. Attribution to Midnight Blizzard — the SVR cyber arm with a documented history of targeting diplomatic, government, and strategic research organizations — is consistent with that collection priority. Russia-linked surveillance operations against travel and transport infrastructure have been publicly documented by Western intelligence services.
Label: Analysis. Objective attribution beyond what Microsoft has stated is not confirmed here.
What to do
No patch applies. Mitigate exposure:
- VPN before anything else on hotel Wi-Fi. Connect a VPN tunnel before any browser activity. The captive portal authentication window requires an unencrypted initial connection — keep that window as narrow as possible, then tunnel everything.
- Reject browser update prompts on unfamiliar networks. Browser updates are delivered through the browser itself or the operating system — not through network redirects or captive portal pages. Any such prompt on hotel Wi-Fi should be treated as hostile.
- Disable auto-connect to remembered hotel networks. Verify the network manually at each stay.
- If an unexpected browser update prompt appeared on hotel Wi-Fi recently: treat the device as potentially compromised. Isolate it, investigate, and rotate all credentials from a separate clean device before reconnecting to corporate systems.
This operation is active per Microsoft’s reporting as of August 1, 2026.
Source: The Hacker News — Microsoft threat intelligence report, published August 1, 2026.
Found this useful? Share it.


