Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
AI Generated Image

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

The Hacker News technology

Key Points:

  • Microsoft reported that a fake browser update distributed via hijacked hotel Wi-Fi networks delivers CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes, linked to the threat actor Storm-2945, a sub-cluster of the Russian-associated APT29 (Cozy Bear).
  • Attackers hijack captive portal gateways serving as DNS resolvers to redirect users to malicious update pages, requiring victims to manually execute payloads; some pages instruct users to run attacker-supplied commands, while others exploit Microsoft's device code authentication flow to gain MFA-satisfied access.
  • CornFlake implants persist by copying themselves to system directories, stealing sensitive data including browser cookies, passwords, clipboard contents, and Microsoft 365 tokens, while a companion PowerShell stealer named ChocoShell harvests Azure AD tokens enabling session replay without browser cookies.
  • Researchers advise travelers to avoid captive portal software updates and use private connections or VPNs to prevent DNS hijacking, while Microsoft recommends blocking device code authentication flows via Conditional Access where unnecessary.
  • The full scope and impact of the attacks remain unclear, with investigations ongoing into the initial compromise vectors, possibly involving exposed management interfaces and weak credentials; Microsoft and ReliaQuest note similarities to other Russian-linked operations but have not confirmed all attributions publicly.

Trending Business

Trending Technology

Trending Health