Midnight Blizzard Uses Captive Portals to Deliver CornFlake RAT and Steal Traveler Credentials
Midnight Blizzard's Storm-2945 resumed hotel captive-portal attacks that deliver CornFlake and steal traveler credentials.
Microsoft says Storm-2945, a Midnight Blizzard subcluster linked to Russia's SVR, resumed CaptiveCrunch on September 29, 2026. Attackers abuse hospitality captive portals, including providers serving seven of the ten largest U.S. hotel chains, to redirect travelers to fake updates and ClickFix lures. A Rust CornFlake variant and in-memory ChocoShell steal browser credentials, Microsoft 365 tokens, and Wi-Fi passwords, while separate pages abuse Entra device-code sign-in. About 70 IP addresses tied to three North American providers were previously identified.