Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Business travelers and hotel guests
Incident: State-sponsored actors are hijacking hotel Wi-Fi portals to deliver surveillance malware via fake updates.
Impact: Full endpoint compromise including webcam/mic access and theft of M365 and Azure AD tokens.
Attacker: Storm-2945 (Midnight Blizzard/APT29)
Analysis: The CaptiveCrunch campaign leverages compromised hotel Wi-Fi gateways to redirect users toward fake browser or OS updates. Once a victim executes the payload, the CornFlake RAT grants attackers full system control, including audio/visual surveillance and token theft. This operation is attributed to Storm-2945, a sub-cluster of the Russian-linked Midnight Blizzard group.
Recommendations: Deploy always-on, full-tunnel VPNs for all corporate travelers to bypass local DNS redirection.; Disable device code authentication via Conditional Access policies where it is not strictly required.; Train employees to reject all software updates or terminal commands prompted by captive portals.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source