Hackers Use Hijacked Hotel Wi-Fi to Spread CornFlake Surveillance Malware

Cybersecurity researchers have uncovered a campaign where compromised hotel Wi-Fi networks redirect guests to fake browser or operating system update pages that install CornFlake, a surveillance-focused remote access trojan (RAT). The campaign is tracked as CaptiveCrunch, with Microsoft attributing it to Storm-2945, a subgroup linked to the Russia-associated APT29 (Cozy Bear).

Hackers Use Hijacked Hotel Wi-Fi to Spread CornFlake Surveillance MalwareHackers Use Hijacked Hotel Wi-Fi to Spread CornFlake Surveillance Malware

Once installed, CornFlake can steal browser cookies, saved passwords, clipboard data, keystrokes, webcam images, microphone audio, and Microsoft 365 authentication tokens, while maintaining persistent remote access. Attackers also abuse Microsoft's device-code authentication flow to gain MFA-approved access to user accounts.

Security experts advise travelers to avoid installing updates through public Wi-Fi portals, use an always-on VPN, verify software updates only through official sources, and remain cautious when prompted to run commands or install unexpected applications while connected to hotel or public networks.


NPAV Total Security – Protects users from phishing, fake updates, and malware.