Summary Points
- Attackers used hijacked hotel Wi-Fi captive portals to deliver CornFlake, a RAT capable of webcam, microphone, keystroke capture, and persistence, via fake browser or OS updates.
- The threat actor, linked to Russian intelligence (SVR) and part of the APT29 cluster, manipulated DNS and redirected victims to malicious pages, enabling malware delivery and account theft.
- CornFlake and related malware can steal browser cookies, passwords, tokens, and perform remote control, posing significant risks of data exfiltration and session hijacking across compromised networks.
Threat, Techniques, and Targets
The threat involves hijacked hotel Wi-Fi networks that deliver fake browser updates to users. Attackers use these fake updates to serve CornFlake, a remote access Trojan (RAT). This RAT can capture webcam images, microphone audio, and keystrokes. They also direct users to click on instructions that run malicious commands. The attackers control the network gateway, which can forge DNS responses and redirect traffic. This means connected devices get sent to fake update pages or malware without the users realizing it.
The attack targets travelers using hotel Wi-Fi, especially those who connect to compromised networks. The attackers have been active since early May across several countries. They focus on hospitality networks, but the exact hotels or vendors involved are not named.
Impact, Security Implications, and Remediation
The impact of this attack is significant. Victims can unknowingly install malware that can access sensitive data like passwords, cookies, and personal videos or audio. The malware also can scan removable media and open remote shells for control. Because the network can redirect traffic, attackers could potentially hijack sessions or steal authentication tokens. This raises concerns about surveillance and data theft on compromised networks.
For protection, Microsoft recommends using a VPN that encrypts DNS queries. Travelers should avoid accepting software updates or security tools from captive portals. They should also use private connections if possible and reject any forced updates. Microsoft suggests implementing Conditional Access controls to block unwanted flows. Because of the complexity of the attack, organizations should seek guidance from their security vendors or authorities to ensure proper mitigation steps are taken.
Expand Your Tech Knowledge
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
