Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Russian spies turn public Wi-Fi into malware delivery systems

Keyloggers, audio-visual surveillance, and token theft on CaptivePortal's agenda as hospitality sector put on alert

Russian spies turn public Wi-Fi into malware delivery systems

Russian foreign intelligence operatives, specifically the SVR group known as Storm-2945, have been using compromised public Wi-Fi networks to deliver malware to unsuspecting users. This malware, named CornFlake, is a full-featured Windows Remote Access Trojan (RAT) that can perform various malicious activities such as keylogging, clipboard monitoring, screenshot capture, audio surveillance, video surveillance, browser credential theft, file exfiltration, USB drive monitoring, and establishing a remote shell.

The attack campaign, known as CaptiveCrunch, was observed to have started in February 2026, with traffic manipulation starting as early as May of the same year. The malware is delivered through fake Windows update prompts and tailored ClickFix prompts on Android devices, aiming to convince users to install malware under the guise of OS updates, driver repairs, or web verification failures.

Brief written by urgent.news from The Register Science's own syndicated text. Machine-written — it may contain errors, so check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech