Hijacked hotel Wi-Fi redirects travellers to CornFlake surveillance malware

A report published on August 1, 2026 details how hijacked hotel Wi-Fi networks have redirected guests to fake browser and operating system updates. Microsoft has tracked the activity across hospitality networks in several countries since early May under the name CaptiveCrunch, attributing it to Storm-2945.
Why captive portals create a credible trap
On networks examined by ReliaQuest, the captive portal gateway also acted as the DNS resolver for connected devices. Administrative control allowed attackers to forge DNS answers and divert automatic connectivity checks to convincing update pages.
The gateway does not infect a laptop silently: the victim must download a payload or execute a supplied command. The command-based lure mirrors ClickFix chains targeting Windows users, while control of the venue’s network makes the instructions appear more trustworthy.
Malware, token theft and attribution
The principal payload, CornFlake, is a Go-based remote access trojan installed as a service named Cloud Sync Service. It can capture webcam images, microphone audio, keystrokes, screenshots and clipboard data; steal browser cookies and saved passwords, including cookies protected by Chrome App-Bound Encryption; inspect removable media; and open a remote shell.
Researchers also found ChocoShell, an in-memory PowerShell stealer targeting Microsoft 365, Azure Active Directory and Web Account Manager tokens. Since July 16, some landing pages have directed guests into Microsoft’s legitimate device-code flow. Entering an attacker-provided code can authorize an MFA-satisfied session controlled by the attacker.
Microsoft links Storm-2945 to Midnight Blizzard, also known as APT29, which the U.S. and U.K. attribute to Russia’s SVR. ReliaQuest noted similarities to APT28 but stopped short of attribution. Neither the number of successful infections nor the initial gateway compromise method has been confirmed.
For businesses, hotel Wi-Fi should be treated as hostile infrastructure. An always-on full-tunnel VPN, corporate DNS, restricted device-code authentication and a firm ban on captive-portal updates materially reduce exposure without relying solely on travellers to identify a polished lure.

