threat-intel
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
High
Summary
A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orchestrated by Storm-2945, a sub-cluster of Midnight Blizzard (APT29/Cozy Bear), a group linked to Russia's Foreign Intelligence Service (SVR). Microsoft has observed this activity since early May, and recommends specific mitigations including using a VPN and blocking Microsoft's device code authentication flow.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
