Back to News
Cybersecurity

Hotel Wi-Fi Exploitation: New Surveillance Malware Threat Uncovered

Recent findings reveal a sophisticated attack leveraging hijacked hotel Wi-Fi to distribute malware via fake updates.

Recent research from Microsoft has uncovered a security threat where hijacked hotel Wi-Fi networks serve fake browser updates to deliver a remote access trojan (RAT) known as CornFlake. This malware, attributed to the threat actor group Storm-2945, is capable of extensive surveillance, including capturing webcam images, audio from microphones, and logging keystrokes. The operation, identified as CaptiveCrunch, highlights the vulnerabilities present in public Wi-Fi networks and the tactics employed by cybercriminals to exploit unsuspecting users.

For businesses, especially those with employees who travel frequently, this serves as a critical reminder of the inherent risks associated with public Wi-Fi. Organizations should implement robust security policies, such as the use of virtual private networks (VPNs) and endpoint protection solutions, to safeguard sensitive data from interception. This incident underscores the importance of user education regarding the dangers of connecting to untrusted networks and the necessity for businesses to adopt comprehensive cybersecurity strategies that address the evolving threat landscape, particularly in the realm of AI and surveillance technologies.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html)*