Hijacked Hotel Wi Fi Networks Used To Deliver CornFlake Surveillance Malware

Published:

Microsoft has disclosed a cyber campaign in which hijacked hotel Wi Fi networks were used to deliver CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, keystrokes, screenshots, browser credentials, and other sensitive information. The campaign, tracked as CaptiveCrunch, has been attributed by Microsoft to Storm 2945, which the company assesses to be an operational sub cluster of Midnight Blizzard, also known as APT29 and Cozy Bear. The broader APT29 group has previously been attributed by the United States and United Kingdom governments to Russia’s Foreign Intelligence Service. According to Microsoft’s findings, the campaign has been active since early May across hospitality networks in several countries, although the company has not identified the affected hotels, venues, or captive portal providers. The initial method used to compromise the affected networks remains under investigation.

Microsoft explained that the attackers gained administrative control of captive portal gateways used by hotel Wi Fi networks. On the compromised networks investigated by ReliaQuest, these gateways also functioned as Domain Name System resolvers for connected devices. This allowed attackers to forge DNS responses and redirect internet traffic to malicious pages designed to impersonate browser or operating system update services. Rather than silently infecting devices, the attackers relied on social engineering by presenting fake software update pages or ClickFix instructions that directed victims to manually execute attacker supplied commands using Windows utilities or terminal windows. Microsoft emphasized that successful infection still required user interaction, including downloading or running the malicious payload. Since July 16, researchers also observed some CaptiveCrunch pages redirecting users to Microsoft’s legitimate device code authentication process. Victims who entered attacker supplied device codes could unknowingly authorize attacker controlled sessions with multi factor authentication already satisfied. Microsoft has recommended that organizations disable device code authentication through Conditional Access wherever it is not required.

Once installed, the Go based CornFlake malware copied itself into the user’s application data folder under the filename svchost32.exe and registered itself as a service named Cloud Sync Service while displaying a fake installation progress window. According to Microsoft, the malware can capture screenshots when systems become idle, record clipboard contents together with active window titles, collect browser cookies and saved passwords, including cookies protected by Chrome App Bound Encryption, scan removable storage devices, and provide attackers with remote shell access. The malware establishes persistence using Registry Run keys and scheduled tasks, while an additional watchdog mechanism automatically restores persistence if defenders remove one of the startup methods. Researchers also identified another malware component named ChocoShell, an in memory PowerShell based information stealer capable of extracting Microsoft 365, Azure Active Directory, and Web Account Manager authentication tokens from Token Broker cache files. These stolen authentication tokens may allow attackers to replay authenticated sessions without requiring browser cookies, increasing the risk of unauthorized access to cloud services.

Although Microsoft and ReliaQuest confirmed active traffic manipulation and malware delivery, neither organization has disclosed the number of successful infections, compromised user accounts, or financial impact resulting from the campaign. Microsoft stated that common networking equipment and management systems were observed across affected hospitality networks, suggesting that multiple locations may have relied on shared infrastructure instead of isolated deployments. ReliaQuest identified overlapping infrastructure and Microsoft impersonation domains several days before Microsoft’s report and noted similarities with tradecraft previously associated with APT28, although it did not attribute the activity because the assessment relied primarily on overlapping techniques. Microsoft, however, maintained its assessment linking CaptiveCrunch to Storm 2945. The company advised travelers to avoid installing browser updates, operating system updates, certificates, troubleshooting tools, or security software offered through hotel captive portals and recommended the use of always on full tunnel virtual private networks that route DNS traffic through trusted corporate infrastructure rather than local network gateways.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img