Attackers operating under the name Storm-2945 compromised hotel Wi-Fi networks to distribute CornFlake, a remote access trojan capable of full surveillance. Microsoft researchers discovered the campaign, dubbed CaptiveCrunch, delivering fake browser updates across hijacked captive portal networks.

CornFlake functions as a comprehensive spyware tool. Once installed, the malware captures webcam footage, records microphone audio, and logs keystrokes. The trojan operates with persistence mechanisms designed to maintain access across system restarts, giving attackers persistent surveillance capabilities on infected devices.

Storm-2945 executes the attack by compromising the Wi-Fi captive portal that users encounter when connecting to hotel networks. Instead of the legitimate login page, targets receive a fake browser update notification. Users who click the prompt unwittingly download CornFlake. The tactic exploits the trust users place in system update dialogs, particularly in public Wi-Fi environments where security awareness drops.

Microsoft assesses Storm-2945 as an operational sub-cluster within Midnight Blizzard, the Russian state-sponsored threat actor previously known as Cozy Bear. This attribution places CaptiveCrunch within Russia's broader cyber espionage infrastructure, though the specific targeting scope remains unclear from available details.

The campaign poses direct risks to business travelers and executives. Hotel Wi-Fi represents an attractive vector because users expect connectivity issues and view update prompts as routine. Once installed, CornFlake gives operators complete remote access including visual surveillance, audio capture, and credential harvesting through keystroke logging.

Organizations should advise employees against installing software updates while connected to public Wi-Fi networks. Updates should only install from official sources using direct connections to vendor websites or corporate VPNs. Hotels and managed Wi-Fi operators must implement stronger authentication protocols for captive portals and regularly audit network configurations for