< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-01T11:59:05+05:30

Hijacked Hotel Wi-Fi Networks Exploit Fake Updates to Deploy Surveillance Malware

A cyberattack exploits hijacked hotel Wi-Fi networks to deliver the CornFlake remote access trojan via fake browser updates, targeting users with surveillance capabilities. The operation, linked to Russia's SVR-affiliated Storm-2945, uses DNS manipulation and phishing techniques to compromise devices, prompting recommendations for encrypted VPN connections and caution with captive portal updates.

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.

Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as

Read original article

*** END OF TRANSMISSION ***