HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Russian‑linked ‘CaptiveCrunch’ Campaign Hijacks Hotel Wi‑Fi Captive Portals to Steal Traveler Credentials and Deploy RATs

A state‑linked group is compromising hotel Wi‑Fi captive portals, redirecting users to phishing pages that harvest Microsoft 365 SSO tokens and delivering the CornFlake RAT and ChocoShell infostealer. The technique highlights gaps in access‑control policies and the need for continuous audit evidence of credential‑management safeguards.

LiveThreat™ Intelligence · 📅 August 05, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
malwarebytes.com

Travelers targeted when logging into hotel Wi‑Fi networks

What Happened — A Russian‑linked threat group, dubbed CaptiveCrunch, is compromising hotel, conference‑center and other hospitality Wi‑Fi captive portals. By hijacking DNS and HTTP traffic, the attackers redirect users to phishing pages that harvest Microsoft 365 SSO tokens, OAuth credentials and device codes, and they also deliver the CornFlake RAT and the file‑less ChocoShell infostealer.

Why It Matters for Compliance & Audit Readiness

  • Credential‑theft via public‑Wi‑Fi is a classic “access‑control” failure that SOC 2 CC 6.2 (Logical Access) and CC 7.1 (Security Awareness) are designed to prevent and evidence.
  • Continuous monitoring of authentication logs, MFA enforcement and documented user‑training programs provide the audit‑ready proof that the organization mitigates this vector.
  • Verisq’s SOC 2 Access Controls capability supplies automated evidence collection (login anomalies, MFA usage, VPN adoption) that can be attached to an audit package.

Who Is Affected – Enterprises that allow employees to travel and use public Wi‑Fi, especially in finance, SaaS, and professional services sectors.

Recommended Actions

  • Enforce MFA for all cloud services and require conditional access policies that block logins from unsecured networks.
  • Mandate VPN use with a kill‑switch for any public‑Wi‑Fi session; log VPN start/stop events for audit evidence.
  • Update security‑awareness training to include captive‑portal phishing and safe‑travel guidelines.
  • Deploy network‑traffic monitoring (DNS‑filtering, TLS inspection) on corporate devices to detect MITM attempts.

Source: Malwarebytes Labs

Technical Notes – The campaign manipulates DNS responses and injects malicious HTTP redirects. Malware families observed: CornFlake (RAT) and ChocoShell (file‑less PowerShell infostealer). Attack vectors: phishing pages, fake Windows‑update dialogs, and MITM proxying. Source: same as above

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →