Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-01 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver CornFlake Surveillance Malware (CaptiveCrunch)

Summary

Microsoft and ReliaQuest detailed CaptiveCrunch, attributed to Storm-2945 (an operational sub-cluster of Midnight Blizzard / APT29 / Russia's SVR). Attackers compromised hotel captive portal gateways, gaining control of DNS resolution to push fake updates delivering CornFlake surveillance malware.

Key Details

  • Date: 2026-08-01
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Threat Actor: Storm-2945 (sub-cluster of Midnight Blizzard / APT29 / Russia's SVR)
  • Campaign Name: CaptiveCrunch
  • Method: Compromised hotel captive portal gateways โ†’ DNS hijacking โ†’ forged DNS answers redirecting to fake browser/OS update pages
  • Technique: ClickFix prompts that copy attack commands to clipboard and instruct victims to paste into Terminal
  • Payload: CornFlake โ€” Go/Rust RAT with webcam capture, microphone recording, and keylogging capabilities

Significance

This campaign presents a specific travel-security risk for Australian government and corporate travellers at SE Asian and Pacific venues, and for NZ government travellers at Pacific Islands Forum and ASEAN dialogues.

Related

Sources