hacker-news · Crawled Aug 1, 2026

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

3 Actors
Read original article ↗

AI Summary

A threat actor dubbed Storm-2945, assessed to be a sub-cluster of the Russian state-sponsored group APT29 (aka Cozy Bear), has hijacked hotel Wi-Fi networks to deliver a surveillance-focused remote access trojan named CornFlake. The attack abuses compromised captive portals to redirect users to fake browser or OS update prompts, which lead to the download of malicious payloads. The CornFlake malware, written in Go, establishes persistence via registry run keys and scheduled tasks, captures keystrokes, screenshots, microphone audio, and browser credentials, and can bypass Chrome's App-Bound Encryption. A related in-memory PowerShell stealer, ChocoShell, harvests Microsoft 365, Azure AD, and WAM tokens from the Token Broker cache. Attackers also leveraged Microsoft's device code authentication flow to gain MFA-satisfied access by tricking users into approving malicious sessions.

AI-extracted · verify before operational use

Extracted Entities 3 found

MITRE ATT&CK TTPs 38 techniques

T1003 OS Credential Dumping · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1133 External Remote Services · Persistence T1136.001 Local Account · Persistence T1185 Browser Session Hijacking · Collection T1204.002 Malicious File · Execution T1555 Credentials from Password Stores · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1570 Lateral Tool Transfer · Lateral Movement T1586 Compromise Accounts · Resource Development T1588 Obtain Capabilities · Resource Development T1556 Modify Authentication Process · Credential Access T1684.001 T1684.001 T1071.004 DNS · Command And Control T1078.004 Cloud Accounts · Defense Evasion T1556.005 Reversible Encryption · Credential Access T1558.003 Kerberoasting · Credential Access