Technology News

Hotel Wi‑Fi Hijack Delivers Remote‑Access Trojan via Fake Browser Update

Remote‑Access Trojan CornFlake steals webcam, audio, keystrokes

A fake browser update distributed over hijacked hotel Wi‑Fi networks has been used to deliver the remote‑access trojan CornFlake, which can capture webcam images, microphone audio, and keystrokes, Microsoft reported.

A recent security report revealed a sophisticated operation that hijacked hotel Wi‑Fi to push a counterfeit browser update, delivering the remote‑access trojan CornFlake.

The malware, dubbed CornFlake, can record webcam images, capture microphone audio, and log keystrokes, enabling attackers to monitor users covertly.

Microsoft's security team identified the distribution vector as a fake update served over compromised hotel networks.

Researchers named the operation CaptiveCrunch and traced it to a threat actor known as Storm‑2945.

Storm‑2945 is classified as an operational sub‑cluster of the broader Midnight Blizzard family, a group that has been linked to various cyber‑espionage campaigns.

The attackers leveraged the trust users place in official software updates to bypass security controls and install the trojan without raising alarms.

Victims reported that the fake update appeared as a legitimate browser update prompt, and once accepted, the installer silently deployed CornFlake onto the device.

Security experts advise users to verify update sources, avoid accepting unsolicited prompts, and monitor for unusual network traffic when using public Wi‑Fi.

Microsoft recommends keeping browsers and operating systems up to date, and using network firewalls or VPNs to reduce exposure to compromised networks.

The incident underscores the growing threat of supply‑chain attacks that exploit legitimate update mechanisms to deliver malware.

Hotel Wi‑Fi Hijack Delivers Remote‑Access Trojan via Fake Browser Update

A recent security report revealed a sophisticated operation that hijacke…

A recent security report revealed a sophisticated operation that hijacke…

A recent security report revealed a sophisticated operation that hijacked hotel Wi‑Fi to push a counterfeit browser update, delivering the remote‑access trojan CornFlake.

The malware, dubbed CornFlake, can record webcam images, capture microphone audio, and log keystrokes, enabling attackers to monitor users covertly.

Microsoft's security team identified the distribution vector as a fake u…

Microsoft's security team identified the distribution vector as a fake u…

Microsoft's security team identified the distribution vector as a fake update served over compromised hotel networks.

Researchers named the operation CaptiveCrunch and traced it to a threat actor known as Storm‑2945.

Storm‑2945 is classified as an operational sub‑cluster of the broader Mi…

Storm‑2945 is classified as an operational sub‑cluster of the broader Mi…

Storm‑2945 is classified as an operational sub‑cluster of the broader Midnight Blizzard family, a group that has been linked to various cyber‑espionage campaigns.

The attackers leveraged the trust users place in official software updates to bypass security controls and install the trojan without raising alarms.

Victims reported that the fake update appeared as a legitimate browser u…

Victims reported that the fake update appeared as a legitimate browser u…

Victims reported that the fake update appeared as a legitimate browser update prompt, and once accepted, the installer silently deployed CornFlake onto the device.

Security experts advise users to verify update sources, avoid accepting unsolicited prompts, and monitor for unusual network traffic when using public Wi‑Fi.

Microsoft recommends keeping browsers and operating systems up to date,…

Microsoft recommends keeping browsers and operating systems up to date,…

Microsoft recommends keeping browsers and operating systems up to date, and using network firewalls or VPNs to reduce exposure to compromised networks.

The incident underscores the growing threat of supply‑chain attacks that exploit legitimate update mechanisms to deliver malware.