Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft warns of Storm-2945, a Midnight Blizzard affiliate hijacking hotel Wi-Fi to deploy the CornFlake RAT through deceptive browser updates.

This article is original editorial commentary written with AI assistance, based on publicly available reporting by The Hacker News. It is reviewed for accuracy and clarity before publication. See the original source linked below.
A sophisticated new cyber-espionage campaign has emerged, targeting high-value travelers through the compromise of hotel Wi-Fi infrastructure. Microsoft’s threat intelligence team recently detailed the activities of a group tracked as Storm-2945, which utilizes hijacked captive portals to distribute a potent remote access trojan (RAT) dubbed “CornFlake.” By intercepting the initial connection process typical of public wireless networks, the attackers present victims with a deceptive prompt for a mandatory browser update. This maneuver exploits the inherent trust users place in administrative network redirects, leading to the silent installation of surveillance software capable of comprehensive data exfiltration.
This development is not an isolated incident but a refined evolution of state-sponsored tradecraft. Microsoft researchers have linked Storm-2945 to Midnight Blizzard—also known as APT29 or Cozy Bear—the notorious threat actor associated with Russia’s Foreign Intelligence Service (SVR). Midnight Blizzard is famously responsible for the 2020 SolarWinds supply chain attack and more recent breaches of Microsoft’s own internal corporate email systems. The involvement of a specialized sub-cluster like Storm-2945 suggests a shift toward more localized, physical-access-adjacent operations, moving beyond broad cloud-based intrusions to target specific individuals in high-stakes environments like international summits and corporate travel hubs.
The technical execution of the CaptiveCrunch operation, as Microsoft calls it, relies on the vulnerability of captive portals—the web pages users must interact with to gain internet access in hotels or airports. When a target connects to the compromised Wi-Fi, the attackers inject malicious code that mimics a legitimate update notification for browsers like Chrome or Edge. Once the user clicks through, the CornFlake RAT is deployed. This malware is designed for total environmental awareness; it can activate webcams, record audio via microphones, log every keystroke, and bypass traditional endpoint security by masquerading as routine administrative traffic.
For the cybersecurity industry, this campaign signals a renewed threat to the "mobile workforce." While many organizations have hardened their cloud perimeters and implemented multi-factor authentication, the physical layer of connectivity remains a significant blind spot. The hijacking of hotel Wi-Fi infrastructure indicates that attackers are successfully targeting third-party service providers who manage these networks. This creates a ripple effect where a single compromise at a hospitality IT vendor can grant a state-sponsored actor access to thousands of corporate and government devices globally, effectively bypassing the robust defenses of the primary target.
The regulatory and market implications are equally profound. Hotels and public space providers now face increasing pressure to demonstrate the security of their guest networks, moving beyond simple bandwidth management to active threat hunting. For enterprise security teams, the incident underscores the insufficiency of traditional VPNs against sophisticated social engineering. If a user is convinced to install a "browser update" at the system level, the most encrypted tunnel in the world will not prevent the RAT from operating locally and shipping data back to its command-and-control servers once a connection is established.
Looking ahead, the industry must watch for a broader adoption of these "hybrid" attack vectors. As Midnight Blizzard continues to diversify its tactics, the distinction between digital and physical security will continue to blur. Observers should monitor whether other state-aligned actors, particularly those from China or Iran, adopt similar captive portal hijacking techniques. Furthermore, the response from browser developers will be critical; we may see a push toward stricter code-signing requirements or OS-level blocks on updates initiated from non-standard network redirects. For now, the primary defense remains a combination of user education and the deployment of zero-trust architectures that treat every public connection as inherently compromised.
Why it matters
- 01The Storm-2945 group, linked to Russia's Midnight Blizzard, is hijacking hotel captive portals to deploy the 'CornFlake' surveillance trojan through fake browser updates.
- 02This campaign marks a strategic shift toward targeting high-value individuals at the physical network layer, bypassing traditional cloud-based security perimeters.
- 03Enterprise security must evolve to address the 'mobile workforce' blind spot, as traditional VPNs cannot protect against system-level malware installed via social engineering.