CornFlake Targets Hotel Wi-Fi

Have you connected to a hotel Wi-Fi in the past few months?
Then this Microsoft report affects you directly.
Since May 2026, hackers linked to Russia’s SVR have been manipulating captive portals at hotels and conference centers to steal corporate credentials from travelers.
These are not isolated attacks on a specific hotel: the pattern suggests access to shared captive portal infrastructure, which extends the scope in a concerning way.

This campaign has a name, confirmed attribution, and its own toolset.
Microsoft Threat Intelligence named it CaptiveCrunch and attributed it to Storm-2945, a subgroup of Midnight Blizzard, also known as APT29 or Cozy Bear. When you attempt to connect to the hotel Wi-Fi, the captive portal has been manipulated to redirect you to fake pages mimicking Windows updates, Google verifications, or seemingly legitimate software installers.
What you download is not an update.
It is CornFlake, a remote access trojan written in Go that installs itself as a Windows service under the name svchost32. Once inside, it logs keystrokes, captures screenshots, audio, and webcam footage, steals browser credentials, and opens an encrypted channel to the attacker’s servers. Each session uses a unique ephemeral key, making it impossible to decrypt intercepted traffic.
There are also indications that Android is in its crosshairs.
The same pages include instructions for installing an APK on mobile devices. Alongside CornFlake operates ChocoShell, a PowerShell-based infostealer that runs entirely in memory, stealing corporate access tokens and WAM tokens that allow full SSO session impersonation without the need for browser cookies.

MFA won’t save you here either.
Since July 16, some CaptiveCrunch pages have added device code phishing: the attacker initiates the authentication request and you, unknowingly, complete the factor on their behalf. The result is an authenticated, valid session in the hands of the adversary.
This pattern connects to something broader.
ReliaQuest documented similar compromises on hotel Wi-Fi gateways redirecting to fake corporate login pages. The technique also echoes FrostArmada, an operation attributed to APT28 or Fancy Bear, which used the same approach against home routers. They do not share infrastructure, but they do share methodology, painting a picture of a Russian intelligence ecosystem with multiple branches perfecting the same play.
The campaign’s control panel was also identified.
It is called FruitStone and disguises itself as a legitimate cloud synchronization console. From there, Storm-2945 operators manage CornFlake implants, deploy payloads, collect stolen credentials, and administer the entire infrastructure with multi-operator access, active agent monitoring, and centralized management of compromised devices.

Microsoft’s practical advice leaves no room for doubt.
Treat hotel, airport, and conference center Wi-Fi as a hostile network. Use mobile data or a personal hotspot whenever possible. Do not run anything a captive portal presents to you as an update or security utility.
And review device code flow now.
Microsoft recommends blocking device code flow through Conditional Access policies in any environment where it is not strictly necessary. ChocoShell also disables Windows Defender signature updates and extracts browser cookies via the Chrome DevTools Protocol, completely bypassing Chrome’s App-Bound encryption.
Traveling connected is no longer innocent.
The next time you look for Wi-Fi in a hotel lobby, remember that someone could be waiting on the other side of that welcome portal.
Stay protected in transit
- ✓Use mobile data or your own hotspot at hotels and airports.
- ✓Do not download or run anything a captive portal requests.
- ✓Block device code flow in your Conditional Access policies.
Do you really know what network you are using when you travel for work?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
The ecosystem of malicious actors and the intelligence gathered about them: APT groups and their attribution, ransomware gangs, law enforcement operations and arrests, dark web markets, threat intelligence reports and the geopolitical backdrop of cybercrime.
RATING
9.4
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




