type: incident ยท created: 2026-08-01 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver CornFlake Surveillance Malware (CaptiveCrunch)
Summary
Microsoft and ReliaQuest detailed CaptiveCrunch, attributed to Storm-2945 (an operational sub-cluster of Midnight Blizzard / APT29 / Russia's SVR). Attackers compromised hotel captive portal gateways, gaining control of DNS resolution to push fake updates delivering CornFlake surveillance malware.
Key Details
- Date: 2026-08-01
- Source: The Hacker News
- Reliability: Tier 2/4 โ Established cyber journalism
- Threat Actor: Storm-2945 (sub-cluster of Midnight Blizzard / APT29 / Russia's SVR)
- Campaign Name: CaptiveCrunch
- Method: Compromised hotel captive portal gateways โ DNS hijacking โ forged DNS answers redirecting to fake browser/OS update pages
- Technique: ClickFix prompts that copy attack commands to clipboard and instruct victims to paste into Terminal
- Payload: CornFlake โ Go/Rust RAT with webcam capture, microphone recording, and keylogging capabilities
Significance
This campaign presents a specific travel-security risk for Australian government and corporate travellers at SE Asian and Pacific venues, and for NZ government travellers at Pacific Islands Forum and ASEAN dialogues.
Related
- Suspected Chinese Speaking Hackers Target Central Asian Governments With Octlurk โ Similar targeting of government travellers