Hijacked hotel Wi-Fi is pushing fake browser updates that install CornFlake, a surveillance RAT capturing webcams, microphones, and keystrokes. Microsoft links the attack to state-sponsored hackers.
You're sitting in a hotel lobby, sipping overpriced coffee, and your browser pops up with a notification: "Update available." It looks routine. It looks harmless. But according to Microsoft's latest threat report, that exact scenario just became a real-world nightmare for travelers who connected to a compromised hotel network.
The attack, tracked as CaptiveCrunch, uses hijacked hotel Wi-Fi to push fake browser updates that install a nasty piece of malware called CornFlake. This isn't your average adware. CornFlake is a remote access trojan (RAT) with some seriously invasive capabilities—it can capture webcam images, record microphone audio, and log every keystroke you type. That means passwords, credit card numbers, private messages—all of it could end up in the hands of attackers.
### Who's Behind This?
Microsoft researchers attribute this operation to a threat actor they call Storm-2945. They assess that this group is an operational sub-cluster of Midnight Blizzard, a well-known Russian state-sponsored hacking group. If you've been following cybersecurity news, you know Midnight Blizzard (also called APT29 or Cozy Bear) has a long history of targeting governments, tech companies, and think tanks. Now, they're apparently turning their attention to travelers.
### How the Attack Works
The attack chain is deceptively simple, which is what makes it so dangerous. Here's how it plays out:
- You connect to what looks like a legitimate hotel Wi-Fi network
- The network is actually controlled by attackers who intercept your traffic
- Your browser shows a fake update notification that looks completely authentic
- If you click "Update," the malware downloads and installs itself
- Once inside, CornFlake starts collecting sensitive data from your device
What's particularly sneaky here is that the fake update looks exactly like a real browser update. The attackers have clearly invested time in making the notification appear legitimate. Most people wouldn't think twice before clicking.
### Why This Matters for You
If you travel for work or pleasure, this is a wake-up call. Hotel Wi-Fi has always been a bit of a security gamble, but this attack takes things to another level. The fact that a state-sponsored group is targeting travelers suggests they're after something specific—likely corporate credentials, government secrets, or intellectual property that business travelers carry with them.
So what can you do to protect yourself?
- **Use a VPN** every time you connect to public Wi-Fi. This encrypts your traffic and makes it much harder for attackers to intercept or modify what you see.
- **Never click update notifications** while on public networks. If your browser needs updating, do it before you travel or use your phone's cellular connection.
- **Disable automatic Wi-Fi connections** on your devices. This prevents your laptop or phone from automatically joining networks without your knowledge.
- **Use your phone as a hotspot** when possible. It's not always convenient, but it's far safer than using hotel Wi-Fi.
- **Keep your browser and operating system updated** before you leave home. If you're already on the latest version, you're less likely to fall for a fake update.
### The Bigger Picture
This attack is a reminder that cyber threats are constantly evolving. The days of obvious phishing emails and sketchy pop-ups are long gone. Today's attackers are sophisticated, patient, and willing to target individuals in creative ways.
What makes this particularly concerning is the setting. Hotels are supposed to be safe spaces—places where you let your guard down. Attackers know this, and they're exploiting that trust.
For IT teams and security professionals, this serves as a critical reminder to educate employees about the risks of public Wi-Fi. A single compromised laptop could give attackers a foothold into your entire corporate network.
### Final Thoughts
This attack isn't just a technical curiosity—it's a real threat to anyone who travels with a laptop or smartphone. The next time you're in a hotel and see a browser update notification, take a moment to think before you click. It might just be the most important decision you make all day.
Stay safe out there, and remember: when it comes to public Wi-Fi, trust nothing and verify everything.