Threat Intelligence Brief
Curated summary with source attribution
Source: securityaffairs.com
Threat Risk: High
Victim: Corporate travelers and hospitality networks
Incident: Manipulation of captive portal DNS and HTTP traffic to deploy the CornFlake RAT.
Impact: Full endpoint compromise and unauthorized access to corporate Microsoft 365 accounts.
Attacker: Storm-2945 (Midnight Blizzard / APT29)
Analysis: The CaptiveCrunch campaign leverages compromised captive portal infrastructure to redirect corporate travelers toward malicious payloads. By deploying the Go-based CornFlake RAT, attackers gain full system control, including keylogging and webcam access, while mimicking legitimate Windows services for persistence. The operation specifically targets Microsoft 365 tokens to bypass traditional authentication and infiltrate corporate environments.
Recommendations: Use a trusted VPN for all traffic when connected to public or hotel Wi-Fi.; Enforce phishing-resistant MFA (FIDO2) to mitigate the risk of stolen session tokens.; Monitor for unusual system services mimicking svchost.exe or unauthorized registry run keys.
Source: Security Affairs / Microsoft Threat Intelligence
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source