A sophisticated cyber espionage campaign is actively targeting corporate travelers by compromising Wi-Fi networks at hospitality venues and large conference centers. According to Security Affairs, the operation is attributed to a sub-cluster of the Russian SVR-linked group known as Midnight Blizzard, which is also identified as APT29 or Cozy Bear. The threat group, designated Storm-2945, has been conducting these attacks since May 2026 by intercepting and manipulating DNS and HTTP traffic processed through captive portals.
The primary objective of this campaign is to infect guest devices with a custom-built remote access trojan (RAT) called CornFlake. Once a user connects to an compromised network, they are redirected through attacker-controlled infrastructure, which facilitates the deployment of the malware. CornFlake is a Go-based Windows trojan designed to mimic legitimate system processes, such as the 'Cloud Sync Service,' to evade detection. The malware establishes multiple layers of persistence, including registry keys and scheduled tasks, ensuring it remains active even if users attempt to manually remove the threat.
Once installed, CornFlake grants the attackers extensive control over the compromised machine. Its capabilities include logging keystrokes, monitoring system clipboards, capturing screenshots, and recording audio or video from peripherals. Furthermore, the malware allows for the exfiltration of sensitive documents and browser credentials, posing a severe risk to business travelers accessing corporate resources. The infrastructure used for this operation suggests a high-level compromise of shared hospitality network management systems, rather than isolated breaches at individual properties. Security professionals urge travelers to utilize robust VPN services and avoid connecting to unverified public networks to mitigate the risk of falling victim to these persistent monitoring activities.
Reader Discussion & Insights