{
  "id": 92624,
  "title": "Russian spies turn public Wi-Fi into malware delivery systems",
  "url": "https://urgent.news/2026/08/03/russian-spies-turn-public-wi-fi-into-malware-delivery-systems",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-03T15:39:05.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/03/russias-svr-borks-public-wi-fis-for-digital-surveillance/5282399"
  },
  "original_language": "en",
  "account": null,
  "summary": "Russian foreign intelligence operatives, specifically the SVR group known as Storm-2945, have been using compromised public Wi-Fi networks to deliver malware to unsuspecting users. This malware, named CornFlake, is a full-featured Windows Remote Access Trojan (RAT) that can perform various malicious activities such as keylogging, clipboard monitoring, screenshot capture, audio surveillance, video surveillance, browser credential theft, file exfiltration, USB drive monitoring, and establishing a remote shell. The attack campaign, known as CaptiveCrunch, was observed to have started in February 2026, with traffic manipulation starting as early as May of the same year. The malware is delivered through fake Windows update prompts and tailored ClickFix prompts on Android devices, aiming to convince users to install malware under the guise of OS updates, driver repairs, or web verification failures.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Russian spies turn public Wi-Fi into malware delivery systems",
        "url": "https://urgent.news/2026/08/03/russian-spies-turn-public-wi-fi-into-malware-delivery-systems-95695",
        "published": "2026-08-03T15:39:05.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}