Russian spies turn public Wi-Fi into malware delivery systems
Keyloggers, audio-visual surveillance, and token theft on CaptivePortal's agenda as hospitality sector put on alert
Microsoft has identified Russian foreign intelligence operatives compromising public Wi-Fi networks at venues such as hotels and conference centers. The perpetrator, Storm-2945, a subdivision of the SVR's Midnight Blizzard, targets captive portal networks to deliver malware, including infostealers, keyloggers and other malicious software.
The attack campaign, known as CaptiveCrunch, has been ongoing since February 2026 with traffic manipulation observed as early as May that same year. Storm-2945 manipulates DNS and HTTP traffic to reroute users through attacker-controlled infrastructure, gaining an adversary-in-the-middle position. Once connected, users are presented with convincing fake Windows update prompts, designed to trick them into installing malware.
One of the malware strains delivered is CornFlake, a Windows Remote Access Trojan (RAT) that provides attackers with persistent access and the ability to capture sensitive information such as keylogs, clipboard data, screenshots, audio and video recordings, and browser credentials. Another component, ChocoShell, is used to extract valuable credentials, including browser session cookies, saved passwords, SSO tokens, and Wi-Fi credentials.
The attacks primarily target Windows machines, but there have also been indications of attempts to target Android devices. Additionally, a portion of the campaign involves device code phishing, where users are tricked into granting attacker access to their Microsoft 365 accounts. Microsoft advises users to avoid connecting to public Wi-Fi networks whenever possible, relying instead on personal hotspots or satellite internet connections.
Organizations are advised to implement technical measures such as passwordless authentication, where possible, and disable device code authentication flows to prevent attackers from gaining access to victims' cloud environments.
Written by urgent.news from The Register's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Russian spies turn public Wi-Fi into malware delivery systems theregister.com