Close Menu
NCIJ Network NCIJ Network
    What's Hot

    FAA certifies Boeing 737 MAX 7 after years of delays

    August 4, 2026

    Greece’s Mitsotakis: EU needs new tools to fight back against weaponized migration – POLITICO

    August 4, 2026

    I tried buying a MacBook Air from Apple today – shipping was delayed by over a month

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • FAA certifies Boeing 737 MAX 7 after years of delays
    • Greece’s Mitsotakis: EU needs new tools to fight back against weaponized migration – POLITICO
    • I tried buying a MacBook Air from Apple today – shipping was delayed by over a month
    • New Pass-ta-key attacks let malware hijack Google-synced passkeys
    • Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too
    • Two new compounds could reveal hidden drivers of Alzheimer’s disease
    • Why did San Diego County stall wage theft reforms?
    • Australia news live: cabinet shake-up in Victoria; Tabcorp and Sportsbet say ‘no evidence’ they provided drugs and escorts to customers | Australia news
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 4, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.

    The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker changed DNS settings on Wi-Fi devices to steal Microsoft 365 accounts.

    Besides attributing the campaign to Russian hackers tracked as Storm-2945 – a sub-cluster of Midnight Blizzard, Microsoft identified two malware families called CornFlake and ChocoShell with capabilities for persistent access, credential theft, surveillance, and data exfiltration.

    image

    Microsoft named the campaign CaptiveCrunch and believes it has been active since at least early May, although the threat actor has been running device and OAuth code phishing operations since February.

    Attack chain

    The attackers manipulate DNS and HTTP traffic on networks served by captive portal equipment, allowing them to intercept user connections to hotel and conference center Wi-Fi networks.

    Like ReliaQuest, Microsoft was unable to determine the exact initial compromise, although it noted signs of breaches in shared infrastructure rather than isolated devices.

    After modifying DNS settings, the attacker can redirect victims to phishing pages that impersonate Microsoft 365 login portals, or to device code phishing pages that abuse Microsoft Entra ID authentication flows. Microsoft observed this activity since July.

    A third option not previously disclosed involves using fake browser and operating system update pages that deliver malware to Windows via ClickFix prompts for user verification.

    ClickFix prompt in CaptiveCrunch campaign
    source: Microsoft

    Microsoft also found evidence in some ClickFix landings indicating that the threat actor is also targeting Android devices to deliver an APK file.

    CornFlake and ChocoShell malware

    Microsoft analyzed the two new Windows malware families and found that CornFlake is a Go-based remote access trojan (RAT) that offers the following capabilities:

    • Remote shell access
    • Keylogging
    • Clipboard monitoring
    • Screenshot capturing
    • Microphone and webcam surveillance
    • Browser credential and cookie theft
    • Microsoft 365 session token theft
    • File exfiltration
    • USB monitoring
    • System reconnaissance

    When executed, CornFlake shows a fake progress window to distract the user while the binary copies to %AppData% for persistence.

    According to the researchers, the bogus window can be configured to appear as a Windows update screen, a Defender virus scan, a disk optimization utility, a network diagnostics tool, a browser update prompt, or a document viewer installer.

    Fake update
    Fake Windows update
    Source: Microsoft

    CornFlake disguises itself as “Cloud Sync Service” to appear as a legitimate Windows component, and uses multiple persistence mechanisms on the host, including Windows service registrations, registry run keys, named tasks, and a watchdog routine designed to restore any of the available persistence mechanisms.

    The second payload, ChocoShell, is an in-memory PowerShell credential stealer that targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.

    Overview of the attack chain
    Overview of the attack chain
    Source: Microsoft

    Based on the extensive comments in the code, Microsoft assesses that AI tools were likely used to develop the two pieces of malware.

    The researchers also discovered an unprotected web-based management panel named FruitStone that the threat actor used to handle infected systems, browse victim files, execute PowerShell commands, and capture screenshots and keystrokes.

    Microsoft recommends treating hotel and conference Wi-Fi as untrusted, using private cellular or managed connections whenever possible, and avoiding software updates or tools offered through captive portals.

    It is also recommended to adopt phishing-resistant authentication with MFA and passkeys, disable Microsoft Entra device code authentication when not needed, and avoid using corporate credentials to register for guest Wi-Fi networks.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Accounts attacks breach custom hotel Malware Microsoft WiFi
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

    Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

    Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    Fake Roblox Xeno script launcher pushes infostealer, RAT malware

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    FAA certifies Boeing 737 MAX 7 after years of delays

    August 4, 2026

    Greece’s Mitsotakis: EU needs new tools to fight back against weaponized migration – POLITICO

    August 4, 2026

    I tried buying a MacBook Air from Apple today – shipping was delayed by over a month

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026
    Latest Posts

    A Russian Spy, Suddenly Cast Into the Spotlight, Flees Japan

    July 23, 2026

    Did Trump accidentally declassify proof Russia tried to help him win 2020 election?

    July 23, 2026

    Trump Puts Section 338 Tariffs on Canada as Greer Foreshadows New Global Duties

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    FAA certifies Boeing 737 MAX 7 after years of delays

    August 4, 2026

    Greece’s Mitsotakis: EU needs new tools to fight back against weaponized migration – POLITICO

    August 4, 2026

    I tried buying a MacBook Air from Apple today – shipping was delayed by over a month

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.