🟠 High  |  Source: The Hacker News


Russian state-linked threat actor Midnight Blizzard (via sub-cluster Storm-2945) has been observed hijacking hotel Wi-Fi networks to serve fake browser update prompts, deploying a remote access trojan called CornFlake. The malware can silently capture webcam footage, microphone audio, and keystrokes from compromised devices. This campaign, tracked as CaptiveCrunch, targets travellers likely connected to business and government sectors.

Security Architect’s Take: Enforce mandatory VPN-before-anything policies for corporate devices on untrusted networks, and block browser update prompts that originate from non-vendor domains via endpoint policy. Consider deploying application allowlisting to prevent unauthorised executables running from browser download paths, particularly on laptops issued to travelling employees or executives.

Original advisory: Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware