# Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware

> Russian threat actor Midnight Blizzard targets hotel Wi-Fi networks using captive portal manipulation, DNS hijacking, and custom malware.

- Published: 2026-08-04T01:28:40.000Z
- Severity: medium
- Category: Threat Intel
- Tags: Midnight Blizzard, APT29, Credential Theft, Phishing, Malware
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
- Canonical: https://runtimerebel.com/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware

## Key points

- Immediate impact: Travelers and conference attendees risk credential theft and account compromise via hijacked hotel and conference center Wi-Fi networks.
- Affected systems: Microsoft 365 accounts, Microsoft Entra ID authentication flows, Windows endpoints, and Android devices.
- Remediation: Treat hotel and conference Wi-Fi as untrusted, use cellular connections, and enforce phishing-resistant MFA.

## Overview of CaptiveCrunch Campaign

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian [threat actor](/glossary#threat-actor) [APT29](https://en.wikipedia.org/wiki/APT29), also tracked as Midnight Blizzard and Storm-2945. According to [BleepingComputer](https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/), the activity—designated as CaptiveCrunch—has been active since at least early May, though device and OAuth code [phishing](/glossary#phishing) operations began as early as February. The campaign abuses captive portal equipment in hotels and conference centers to manipulate DNS and HTTP traffic, allowing operators to intercept user connections.

While [initial access](/glossary#initial-access) vectors remain undetermined, researchers noted signs of compromise affecting shared network infrastructure rather than isolated endpoints. Security teams investigating these incidents should review how to detect hotel Wi-Fi [malware](/glossary#malware) campaigns by monitoring anomalous DNS modifications and unexpected captive portal redirection behaviors across roaming endpoints.

## Technical Analysis of CornFlake and ChocoShell

During the campaign, the threat actor deploys custom tooling designed for [persistence](/glossary#persistence), [credential harvesting](/glossary#credential-harvesting), and surveillance. Microsoft identified two primary malware families used in these attacks:

* **CornFlake**: A Go-based [remote access trojan (RAT)](/glossary#remote-access-trojan-rat) that displays a bogus progress window to distract users while copying the binary to the `%AppData%` directory. It disguises itself as a legitimate component named "Cloud Sync Service" and uses multiple persistence vectors, including registry run keys, scheduled tasks, and a watchdog routine.
* **ChocoShell**: An in-memory PowerShell credential stealer that harvests browser cookies, saved passwords, Wi-Fi credentials, and Microsoft 365 or Azure AD tokens.

Furthermore, code analysis suggests that artificial intelligence tools were likely used to develop these payloads. Operators manage infected systems using an unprotected web-based management panel known as FruitStone, which enables file browsing, command execution, and screenshot capture.

### Delivery Mechanisms

Attackers utilize multiple methods after intercepting network traffic:
* Redirecting victims to credential harvesting pages impersonating Microsoft 365 login portals.
* Abusing Microsoft Entra ID device code authentication flows.
* Deploying fake browser or operating system update pages that deliver Windows malware via ClickFix prompts, alongside Android APK payloads.

## Mitigation and Defense Strategies

Defenders must assume that public guest networks are hostile environments. Organizations should implement strict travel security guidelines to protect corporate identities from interception:

* **Network Isolation**: Mandate that employees avoid hotel and conference Wi-Fi, preferring private cellular connections or enterprise-managed virtual private networks.
* **Authentication [Hardening](/glossary#hardening)**: Enforce phishing-resistant multi-factor authentication, such as hardware security keys and passkeys, while disabling unused Microsoft Entra device code authentication flows.
* **User Awareness**: Educate staff to reject software updates, browser installers, or verification prompts encountered through captive portal landing pages.

**Related:** [ChatGPT Share Link Abuse: Fake Outages Deliver Malware](/blog/chatgpt-share-link-abuse-fake-outages-deliver-malware), [FIFA World Cup 2026 Phishing: Fake Domains and Banking Malware](/blog/fifa-world-cup-2026-phishing-fake-domains-and-banking-malware)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware
