Russian Hackers Target Hospitality Wi-Fi with Custom Malware
A recent global campaign targeting hospitality Wi-Fi networks has been linked to Russian threat actor Midnight Blizzard, also known as APT29. The attackers use custom malware to breach Microsoft 365 accounts by manipulating DNS and HTTP traffic on networks served by captive portal equipment.
Microsoft identified two new Windows malware families: CornFlake and ChocoShell. CornFlake is a Go-based remote access trojan (RAT) with capabilities for persistent access, credential theft, surveillance, and data exfiltration. It disguises itself as "Cloud Sync Service" to appear as a legitimate Windows component.
ChocoShell is an in-memory PowerShell credential stealer that targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. The attackers use AI tools to develop the malware, and an unprotected web-based management panel named FruitStone was used to handle infected systems and execute commands.
Microsoft recommends treating hotel and conference Wi-Fi as untrusted, using private cellular or managed connections whenever possible, and adopting phishing-resistant authentication with MFA and passkeys. The CaptiveCrunch campaign has been active since at least early May, although the threat actor has been running device and OAuth code phishing operations since February.