Your Hotel Wi-Fi Could Be Serving You Malware—Here's What to Know

·
Listen to this article~5 min
Your Hotel Wi-Fi Could Be Serving You Malware—Here's What to Know

Hackers are hijacking hotel Wi-Fi to push fake browser updates and install CornFlake, a surveillance RAT that captures webcam, mic, and keystrokes. Learn how to stay safe.

You're sitting in a hotel lobby, sipping overpriced coffee, and your browser pops up with a notification: "Update available." It looks legitimate. It seems urgent. You click it without thinking twice. That's exactly what the attackers behind a new campaign called CaptiveCrunch are counting on. Microsoft's latest threat intelligence report reveals a nasty trick: hackers hijack hotel Wi-Fi networks and push fake browser updates to unsuspecting guests. The payload? A remote access trojan (RAT) named CornFlake that can capture webcam images, record microphone audio, and log every keystroke you type. If that sounds like a nightmare scenario, you're not wrong. ### The Attack Chain: From Lobby to Lockdown The attack starts with something most travelers do without a second thought—connecting to the hotel's Wi-Fi. Once you're on the network, the bad guys intercept your traffic and redirect you to a page that looks like a standard browser update prompt. It's convincing. It's polished. And it's completely fake. When you click "Update," you're not getting a patch. You're downloading CornFlake, a piece of surveillance malware that burrows into your system and starts collecting data. Microsoft researchers track this operation as CaptiveCrunch and attribute it to a threat group called Storm-2945, which they assess to be an operational sub-cluster of the notorious Midnight Blizzard (also known as APT29). That's the same group linked to some of the most sophisticated state-sponsored attacks in recent memory. ### What CornFlake Can Do to You Once CornFlake is on your machine, it's not just stealing passwords. Here's what this RAT is capable of: - **Webcam hijacking:** It can turn on your camera without you knowing, capturing images of your hotel room, your face, and anything else in view. - **Microphone recording:** It can listen in on your conversations, whether you're on a call or just chatting with a colleague in the room. - **Keystroke logging:** Every password, every credit card number, every personal message you type gets recorded and sent back to the attackers. - **Data exfiltration:** The malware can quietly siphon files from your device, including documents, photos, and credentials stored in browsers. That's a full surveillance package, and it's all happening in the background while you're trying to relax after a long flight. ### Why Hotel Wi-Fi Is a Prime Target Hotels are a perfect hunting ground for this kind of attack. Think about it: travelers are tired, distracted, and more likely to click on something that looks official. They're also often carrying high-value data—corporate laptops, personal devices, financial information. And hotel networks are notoriously under-secured, with many guests connecting to the same unencrypted access point. What's worse, the attackers don't need to break into the hotel's systems directly. They can set up a rogue access point with a similar name, like "Hotel_Guest_WiFi" instead of "Hotel_Guest_WiFi_5G," and wait for victims to connect. Once you're on their network, they control the flow of traffic. ### How to Protect Yourself on Public Networks You don't have to swear off hotel Wi-Fi forever, but you should change your habits. Here are some practical steps to keep yourself safe: - **Use a VPN:** A good virtual private network encrypts your traffic, making it nearly impossible for attackers to intercept or redirect it. - **Verify updates manually:** If your browser asks you to update, close the tab and go directly to the official website. Don't click links in pop-ups or notifications. - **Turn off auto-connect:** Disable the setting that automatically joins available networks. Always choose the network manually and confirm it's the right one. - **Enable two-factor authentication:** Even if your credentials are stolen, 2FA can stop attackers from getting into your accounts. - **Keep your software updated:** Regular updates patch vulnerabilities that malware like CornFlake exploits. ### The Bottom Line This campaign is a wake-up call. It's not just about shady downloads or phishing emails anymore—attackers are weaponizing the very infrastructure we rely on when we travel. The next time you're in a hotel lobby and see that update prompt, remember: it might be the real thing, or it might be a trap. A few seconds of caution can save you from a world of trouble. Stay vigilant, use a VPN, and never trust a pop-up over a direct visit to the official site. Your privacy—and your webcam—will thank you.