Utopia Tech
SecurityAI-assisted1 min read

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Microsoft has identified a cyberattack operation called CaptiveCrunch, attributed to Storm-2945 (a sub-cluster of Midnight Blizzard), that compromises hotel Wi-Fi networks to deliver fake browser updates. The malicious updates install CornFlake, a remote access trojan capable of capturing webcam footage, audio recordings, and keystrokes from infected devices. This attack vector specifically target

UT

Utopia Tech

August 1, 2026 · 1 min read

Share

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content