Hijacked hotel Wi-Fi redirects travellers to CornFlake surveillance malware

A report published on August 1, 2026 details how hijacked hotel Wi-Fi networks have redirected guests to fake browser and operating system updates. Microsoft has tracked the activity across hospitality networks in several countries since early May under the name CaptiveCrunch, attributing it to Storm-2945.
Why captive portals create a credible trap
On networks examined by ReliaQuest, the captive portal gateway also acted as the DNS resolver for connected devices. Administrative control allowed attackers to forge DNS answers and divert automatic connectivity checks to convincing update pages.
The gateway does not infect a laptop silently: the victim must download a payload or execute a supplied command. The command-based lure mirrors ClickFix chains targeting Windows users, while control of the venue’s network makes the instructions appear more trustworthy.
Malware, token theft and attribution
The principal payload, CornFlake, is a Go-based remote access trojan installed as a service named Cloud Sync Service. It can capture webcam images, microphone audio, keystrokes, screenshots and clipboard data; steal browser cookies and saved passwords, including cookies protected by Chrome App-Bound Encryption; inspect removable media; and open a remote shell.
Researchers also found ChocoShell, an in-memory PowerShell stealer targeting Microsoft 365, Azure Active Directory and Web Account Manager tokens. Since July 16, some landing pages have directed guests into Microsoft’s legitimate device-code flow. Entering an attacker-provided code can authorize an MFA-satisfied session controlled by the attacker.
Microsoft links Storm-2945 to Midnight Blizzard, also known as APT29, which the U.S. and U.K. attribute to Russia’s SVR. ReliaQuest noted similarities to APT28 but stopped short of attribution. Neither the number of successful infections nor the initial gateway compromise method has been confirmed.
For businesses, hotel Wi-Fi should be treated as hostile infrastructure. An always-on full-tunnel VPN, corporate DNS, restricted device-code authentication and a firm ban on captive-portal updates materially reduce exposure without relying solely on travellers to identify a polished lure.
CornFlake malware: what it is and how the hotel Wi-Fi attack works
CornFlake is a Go-based remote access trojan delivered through convincing fake update pages on compromised hotel networks. Joining the Wi-Fi alone does not silently infect a device: the traveller must download a payload or run a supplied command.
The infection chain in brief
Attackers with administrative control of a captive portal gateway can forge DNS responses and redirect connectivity checks to fake browser or operating system update pages. The trusted setting of a hotel network makes the instructions appear credible, but user action is still required.
- The captive portal redirects the traveller to a fake update page.
- The victim downloads a payload or executes a displayed command.
- CornFlake installs as a service named Cloud Sync Service.
- Some pages instead abuse Microsoft's legitimate device-code flow.
What CornFlake can access
Once installed, CornFlake provides broad surveillance and remote-control functions. The reported tool can collect information from the device, steal browser data and open a remote shell.
- It can capture screenshots, keystrokes, webcam images and microphone audio.
- It can collect clipboard data, browser cookies and saved passwords.
- It can inspect removable media and open a remote shell.
- Related activity includes ChocoShell targeting Microsoft cloud and account tokens.
Practical controls for business travellers
Businesses should treat hotel Wi-Fi as untrusted infrastructure rather than relying on travellers to recognise a polished lure. The measures described in the report reduce exposure at the network, identity and user-policy levels.
- Use an always-on, full-tunnel VPN on corporate devices.
- Route requests through corporate DNS.
- Restrict device-code authentication where appropriate.
- Do not install updates offered by a captive portal.
Frequently asked questions
What is CornFlake malware?
CornFlake is a Go-based remote access trojan reported in attacks involving hijacked hotel Wi-Fi. It can capture device activity, steal browser data and provide a remote shell.
Can hotel Wi-Fi install CornFlake automatically?
The examined gateway did not infect laptops simply when they joined the network. A victim still had to download a payload or execute a command presented by the fake update page.
Why are captive portals effective for this attack?
Travellers expect captive portals to interrupt browsing and display network instructions. If attackers control the gateway and DNS responses, a fake update prompt can appear to be part of the venue's normal connection process.
How can organisations reduce exposure?
The reported precautions include an always-on full-tunnel VPN, corporate DNS, restrictions on device-code authentication and a clear ban on installing captive-portal updates.

