CaptiveCrunch Campaign delivering CornFlake RAT (Storm-2945 / Midnight Blizzard sub-cluster)
First seen Aug 3, 2026 · Updated Aug 3, 2026
Microsoft has identified a campaign, tracked as CaptiveCrunch, in which threat actors hijack hotel Wi-Fi captive portals to serve fake browser update prompts. Victims who install the fake update are infected with CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The activity is attributed to Storm-2945, assessed as an operational sub-cluster of the Russian state-sponsored group Midnight Blizzard (APT29).
Technical Analysis
The attack chain begins with adversary-in-the-middle manipulation of hotel Wi-Fi captive portals, redirecting guests to a spoofed browser-update page that social-engineers execution of a malicious installer. Once deployed, CornFlake RAT establishes persistence and provides full surveillance capability including webcam/microphone capture and keystroke logging, giving operators access to credentials, session tokens, and sensitive communications typed on the compromised host. Given the targeting of business travelers, the campaign likely aims at espionage and credential harvesting for follow-on access to corporate networks and cloud accounts. Any credentials, API keys, or session tokens for AI agent platforms, LLM tool-use consoles, or RAG orchestration dashboards entered on an infected device would be captured via keylogging, potentially enabling account takeover and unauthorized use of agent infrastructure and connected data sources.
Affected Systems
Windows workstations and laptops used by travelers connecting to hotel/public Wi-Fi networks; browsers prompted with fake update dialogs (Chrome, Edge, Firefox update lures); any endpoint lacking EDR/behavioral protection against unsigned installer execution
Indicators of Compromise
- Fake browser update installer masquerading as Chrome/Edge/Firefox updater
- CornFlake RAT payload (specific hash not disclosed in source reporting)
- Malicious captive portal redirect pages hosted on compromised hotel Wi-Fi infrastructure
- C2 infrastructure attributed to Storm-2945 (specific domains/IPs pending full Microsoft report disclosure)
Remediation Steps
- 1
Avoid unsolicited browser updates on public networks
Never install browser or software updates prompted through captive portals or public Wi-Fi; always update via the browser's built-in updater or official vendor site.
- 2
Use VPN on untrusted networks
Require corporate VPN for all traffic when connecting to hotel or public Wi-Fi to prevent captive portal injection and traffic manipulation.
- 3
Deploy EDR and application allowlisting
Ensure endpoint detection and response tools flag unsigned or anomalous installer execution, and enforce application allowlisting on traveling employee devices.
- 4
Rotate exposed credentials
Any credentials, API keys, or tokens (including those for AI agent platforms, cloud consoles, or RAG systems) entered on potentially compromised devices should be rotated immediately.
- 5
User awareness training
Train employees, especially frequent travelers, to recognize fake update prompts and captive portal phishing tactics.
- 6
Network segmentation and monitoring
Monitor for CornFlake RAT indicators (webcam/mic access anomalies, unexpected keylogging processes) and segment corporate access from personal/travel devices.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.