Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
ID: ec6c6d11-95a9-5839-80fd-a6c3e30537d1
STIX ID: report--ec6c6d11-95a9-5839-80fd-a6c3e30537d1
Feed Name: The Hacker News
Microsoft and ReliaQuest describe the CaptiveCrunch campaign where attackers compromised hotel captive-portal gateways (acting as DNS resolvers) to redirect guests to fake browser/OS updates that install CornFlake RAT and ChocoShell token-stealer; the implants capture webcam/microphone, keystrokes, cookies, and authentication tokens and employ persistence and watchdogs. Microsoft attributes the operation to Storm-2945 (assessed as linked to APT29/Midnight Blizzard), documents device-code MFA abuse and token theft enabling session replay, and recommends always-on VPNs, rejecting captive-portal updates, and Conditional Access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
