Hijacked Hotel Wi‑Fi Serves Fake Browser Updates to Deploy CornFlake RAT
What Happened — Researchers observed that attackers compromised the captive‑portal infrastructure of several hotel Wi‑Fi networks and injected a counterfeit browser‑update page. When guests accepted the “update,” the page delivered the CornFlake remote‑access trojan, which can record webcam video, capture microphone audio and log keystrokes. Microsoft attributes the operation to the CaptiveCrunch campaign, linked to the Storm‑2945 sub‑cluster of the Midnight Blizzard threat group.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a failure of network‑security controls (SOC 2 CC6.1) that should prevent unauthorized content injection on public‑access infrastructure.
- Highlights the need for continuous evidence collection on captive‑portal configurations and change‑management processes (SOC 2 CC7.1, CC7.2).
- Provides a concrete example of why control‑mapping and automated audit‑ready monitoring are essential to prove that network segmentation and user‑device validation controls are operating effectively.
Who Is Affected — Hospitality operators (hotels, resorts, conference centers) and any organization that offers guest Wi‑Fi; indirectly, travelers and business users who connect to those networks.
Recommended Actions
- Map the captive‑portal and Wi‑Fi infrastructure to SOC 2 control requirements (CC6.1, CC7.1) and document the configuration baseline.
- Deploy continuous monitoring tools that capture configuration drift and unauthorized content injection as immutable audit evidence.
- Enforce TLS‑encrypted captive‑portal redirects, digitally sign any software‑update prompts, and educate guests on verifying update sources.
- Conduct a rapid risk assessment of all public‑access networks and update incident‑response playbooks to include “Wi‑Fi content‑injection” scenarios.
Source: The Hacker News
Technical Notes — Attack vector: hijacked captive‑portal (misconfiguration/compromise of hotel Wi‑Fi infrastructure). Malware: CornFlake RAT (capable of webcam, microphone, keystroke capture). No specific CVE is cited; the threat relies on social engineering of a fake browser update.