Russian spies turn public Wi-Fi into malware delivery systems

JeremyPatMartin1 pts0 comments

Russia’s SVR borks public Wi-Fis for digital surveillance

Jump to main content

Search

REG AD

Security

Russian spies turn public Wi-Fi into malware delivery systems

Keyloggers, audio-visual surveillance, and token theft on CaptivePortal's agenda as hospitality sector put on alert

Connor Jones

Connor<br>Jones

Cybersecurity reporter

Published<br>mon 3 Aug 2026 // 16:39 UTC

Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are compromising captive portal networks to deliver infostealers, keyloggers, and other malware.<br>With the help of ReliaQuest's earlier work, Redmond fingered Storm-2945, a subdivision of the SVR's Midnight Blizzard (aka Nobellium), in an attack campaign targeting users of public Wi-Fi networks at places like hotels, conference centers, and other shared venues in the hospitality sector.<br>Microsoft is still trying to determine how the hackers initially compromise captive-portal networks. The broader AI-assisted operation dates to February 2026, with traffic manipulation observed since early May.

REG AD

After gaining control of the network layer, Storm-2945 manipulates DNS and HTTP traffic to reroute users through attacker-controlled infrastructure, Microsoft said. The crew also abuses operating systems' connectivity checks to trigger malicious prompts and redirects.

REG AD

This gives the attackers an adversary-in-the-middle (AitM) position.<br>Such prompts adopt ClickFix-style methods, which in some cases try to convince public Wi-Fi users to install malware under the guise of OS updates, driver repairs, and web verification failures.<br>Users who follow through on the instructions provided in the prompts may then find their device infected with malware.<br>Microsoft calls the campaign "CaptiveCrunch." One of the malware strains it delivers is CornFlake.<br>Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks. After presenting users with a "convincing" fake Windows update progress window, it provides attackers with a wealth of capabilities once installed.<br>These include:<br>Keylogging

Clipboard monitoring

Screenshot capture

Audio surveillance

Video surveillance

Browser credential theft

File exfiltration

USB drive monitoring

Security posture sweep

Remote shell

Microsoft also said that CornFlake exposes a localhost HTTP API server to transform the malware into a modular platform, delivering additional payloads such as ChocoShell, a PowerShell-based infostealer.

REG AD

ChocoShell is delivered and executed entirely in-memory, Microsoft said. SVR uses it primarily to suck up victims' browser session cookies, saved passwords, SSO tokens, and Wi-Fi credentials.<br>Microsoft neatly summarized the two: "Where CornFlake provides the operator with a persistent, long-running foothold on the device, ChocoShell is designed to extract the most operationally valuable credentials, giving the operator access to victim cloud environments."<br>The attacks primarily target Windows machines, but Microsoft has also seen indications of ClickFix prompts tailored to Android devices, encouraging users to download and install an APK file.<br>In addition to the malware element, "a portion" of SVR's CaptiveCrunch activity is devoted to device code phishing.<br>Users sent to attacker-controlled landing pages may be instructed to enter a device code on a legitimate Microsoft authentication page, unwittingly authorizing the attacker's session.<br>Device code phishing exploits a legitimate OAuth flow, typically reserved for devices that struggle to open browsers, such as smart TVs.<br>In such scenarios, attackers request an authentication code from Microsoft, which they then send to phishing targets. In the CaptiveCrunch campaign, this looks like a fake landing page, served to the user thanks to the AitM component of the attack.<br>Targets are then asked to copy the code, which was originally given to the attacker, open a legitimate Microsoft authentication window, enter the code, and choose which account they wish to authenticate. Choosing the account completes the authentication flow, but in turn authenticates the attacker into the chosen account.

REG AD

MORE CONTEXT

Gizmodo readers hit with ClickFix malware prompts after account compromise

Microsoft sheds some light on Russian email heist – and how to learn from Redmond's mistakes

World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection

Iran targets M365 accounts with password-spraying attacks

This gives the attacker a valid OAuth token for the victim's Microsoft 365 account, potentially granting access to cloud data permitted by the token until it expires or is revoked.<br>Device code phishing is not a new or unique attack, but can be an effective route to bypassing MFA, especially when an attacker already controls the flow of traffic after a captive portal...

microsoft malware users attacker code public

Related Articles