Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The 5 laptop features worth spending extra on (and 3 that are mostly hype)

    August 1, 2026

    Ruby on Rails Patches Critical Vulnerability

    August 1, 2026

    Russia Expands Crypto Mining Ban to Moscow

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The 5 laptop features worth spending extra on (and 3 that are mostly hype)
    • Ruby on Rails Patches Critical Vulnerability
    • Russia Expands Crypto Mining Ban to Moscow
    • Corey Ruiz shooting: what happened, what’s next and the reporting to know
    • India’s Modi says he forgives students who abused him in Cockroach protests | Narendra Modi News
    • Ceuta crisis: 22 EU leaders gang up against Spain’s Sánchez over his migration policy
    • On the ground in the English seaside town rightwing influencers say is being ‘invaded’ | Immigration and asylum
    • The ban on robot vacuums won’t make them safer, only worse
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 1, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 01, 2026Malware / Cyber Espionage

    A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.

    Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as APT29 and Cozy Bear. The U.S. and U.K. governments attribute the broader actor to Russia’s Foreign Intelligence Service (SVR).

    On the compromised networks ReliaQuest investigated, the captive portal gateway also served as the DNS resolver assigned to connected devices. Administrative control of that gateway let the attackers forge Domain Name System (DNS) answers and redirect the resulting traffic. They could then redirect a laptop’s automatic connectivity check to a fake browser or operating system update.

    Some pages use ClickFix instructions that tell victims to open a terminal or another Windows utility and run an attacker-supplied command. The gateway controls where the user is sent, but it does not silently infect the endpoint. The victim still has to download or execute the payload.

    Microsoft has observed the traffic manipulation since early May across hospitality networks in several countries, but it has not named a hotel, venue, or captive portal vendor. ReliaQuest recommends an always-on, full-tunnel virtual private network (VPN), which sends DNS queries through corporate resolvers before the venue’s gateway can answer them.

    Cybersecurity

    Researchers advise travelers to use private connections and reject software updates, certificates, browser updates, troubleshooting tools, or security utilities offered through captive portals.

    Since July 16, some CaptiveCrunch landing pages have redirected guests into Microsoft’s device code authentication flow. Entering the attacker-supplied code on Microsoft’s legitimate sign-in page can grant the attacker-controlled session multi-factor authentication (MFA)-satisfied access. Microsoft recommends blocking the flow through Conditional Access wherever it is not needed.

    CornFlake, a Go-based implant, copies itself to %APPDATA%svchost32svchost32.exe and registers the svchost32 service under the display name Cloud Sync Service. A fake progress window holds the victim’s attention while this happens.

    Microsoft’s analysis says the implant can take idle-triggered screenshots, record clipboard contents with the active window title, steal browser cookies and saved passwords, including cookies protected by Chrome App-Bound Encryption, scan removable media, and open a remote shell. It also uses a Registry Run key and a scheduled task, while a watchdog restores any persistence mechanism defenders remove.

    Researchers also identified ChocoShell, an in-memory PowerShell stealer. It collects Microsoft 365 and Azure Active Directory access and refresh tokens, plus Web Account Manager (WAM) tokens, from .tbres files in the Token Broker cache. The stolen tokens can enable session replay without a browser cookie.

    The reports document active redirection and malware delivery, but do not quantify their reach or conversion. Without counts of successful executions, device-code approvals, or stolen accounts, the public record does not show how often a redirect became a compromise.

    Microsoft found common equipment and management systems across the affected networks, which it says could reflect access to shared services within portions of the captive portal ecosystem. If so, the compromises may not have been isolated to individual venues. Microsoft has not named any affected provider.

    Cybersecurity

    ReliaQuest documented the same Microsoft-impersonating domains and overlapping infrastructure eight days earlier. It said the tradecraft resembled APT28, the GRU unit also called Fancy Bear and Forest Blizzard, but stopped short of attribution because the assessment rests on TTP overlap rather than direct technical linkage.

    Microsoft acknowledges the similarity to the Forest Blizzard router hijacking it disclosed in April while attributing CaptiveCrunch to Storm-2945.

    The U.K. National Cyber Security Centre and its international partners assess that APT29 is almost certainly part of Russia’s Foreign Intelligence Service. That government attribution covers the broader APT29 group. The CaptiveCrunch-to-Storm-2945 link remains Microsoft’s assessment. No separate public technical report has independently corroborated it.

    The initial compromise vector remains under investigation. ReliaQuest assesses with low-to-medium confidence that a combination of exposed management interfaces and weak or reused administrator credentials may have provided access, but said visibility constraints prevented confirmation.

    deliver Fake Hijacked hotel Malware pushes Surveillance updates WiFi
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Ruby on Rails Patches Critical Vulnerability

    Hacker uses DeepSeek AI to autonomously attack vulnerable servers

    Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

    CISA Issues New SBOM Guidance. Did They Get It Right?

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    Critical Code Execution Vulnerability Patched in TeamCity 

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The 5 laptop features worth spending extra on (and 3 that are mostly hype)

    August 1, 2026

    Ruby on Rails Patches Critical Vulnerability

    August 1, 2026

    Russia Expands Crypto Mining Ban to Moscow

    August 1, 2026

    Corey Ruiz shooting: what happened, what’s next and the reporting to know

    August 1, 2026
    Latest Posts

    New to Linux? This 10-day checklist will help you settle in nice and easy

    July 22, 2026

    Tories ask HMRC to investigate whether Nigel Farage owes tax on £5m gift | Nigel Farage

    July 22, 2026

    Greece derails EU’s Russia sanctions plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The 5 laptop features worth spending extra on (and 3 that are mostly hype)

    August 1, 2026

    Ruby on Rails Patches Critical Vulnerability

    August 1, 2026

    Russia Expands Crypto Mining Ban to Moscow

    August 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.