Is Your Hotel Wi-Fi Safe From Russian Cyber-Espionage?

Rupert Marais has spent over a decade navigating the labyrinthine world of endpoint security and network management, earning a reputation as a leading authority on how state-sponsored actors exploit common infrastructure. As our in-house Security Specialist, Rupert has a keen eye for the subtle anomalies that signal a massive breach, particularly within the often-overlooked ecosystems of hospitality Wi-Fi. In this conversation, he sheds light on the sophisticated “CaptiveCrunch” operation, an campaign attributed to the formidable Storm-2945, which transforms a routine hotel login into a gateway for high-level surveillance.

This discussion explores the mechanics of DNS hijacking and how attackers turn a captive portal into a weaponized redirection tool. We examine the intricate details of the CornFlake trojan, its Go-based architecture, and its ability to remain hidden while exfiltrating sensitive data like webcam feeds and browser cookies. Rupert also provides deep insights into the ChocoShell stealer and the abuse of Microsoft’s device code authentication flow, highlighting why traditional security measures often fail against such targeted tradecraft.

Beyond simple redirects, how does the manipulation of a captive portal’s DNS resolver create an invisible trap for unsuspecting travelers?

The danger lies in the inherent trust we place in the “official” gateway of a hotel or venue. When the captive portal gateway also serves as the assigned DNS resolver, an attacker with administrative control can effectively rewrite the map of the internet for every connected device. They don’t just send you to a different site; they forge Domain Name System answers that redirect a laptop’s automatic connectivity checks to malicious infrastructure without the user ever typing a URL. Since early May, we have seen this traffic manipulation occurring across hospitality networks in several countries, where the gateway silently steers traffic toward fake browser or operating system updates. It is a chillingly efficient method because the victim believes they are simply interacting with a necessary network requirement, making the eventual prompt to run an attacker-supplied command through a terminal feel like a legitimate troubleshooting step rather than a breach.

How does the CornFlake implant use psychological deception and specific technical masking to remain undetected during the initial infection?

The CornFlake implant is a masterclass in distraction, using a Go-based architecture to carry out its work while the user is looking the other way. Once it lands on a system, it copies itself to a very specific and inconspicuous path—%APPDATA%\svchost32\svchost32.exe—and registers itself as a service under the reassuring display name “Cloud Sync Service.” While this malicious file is being written and persistence is being established, the attackers display a fake progress window on the screen. This window is designed to hold the victim’s attention, making them wait patiently for a “download” or “update” to finish, while in the background, the malware is actually busy taking idle-triggered screenshots and recording clipboard contents. It even uses a Registry Run key and a scheduled task, backed by a watchdog process that automatically restores any persistence mechanism if a defender tries to remove it, ensuring the surveillance remains uninterrupted.

What makes the ChocoShell stealer particularly dangerous for corporate users who rely on Microsoft 365 and Azure Active Directory?

ChocoShell represents a specialized threat because it targets the very heart of modern corporate authentication. This in-memory PowerShell stealer is designed to hunt for Microsoft 365 and Azure Active Directory access and refresh tokens, specifically looking for .tbres files tucked away in the Token Broker cache. By extracting these Web Account Manager tokens, the adversary can perform a session replay, effectively impersonating the user without needing a browser cookie. This is a devastating blow to traditional perimeter defenses because it bypasses many of the hurdles that usually stop remote attackers. The theft of these tokens allows the actor to move laterally through a corporate environment with the same privileges as the victim, all while the user remains completely unaware that their identity has been cloned from a hotel lobby.

How has the shift toward exploiting Microsoft’s device code authentication flow changed the success rate of these redirection campaigns?

Since July 16, we have observed a significant evolution where CaptiveCrunch landing pages redirect guests into a legitimate Microsoft sign-in flow using device code authentication. This is an incredibly clever bit of tradecraft because it leverages the user’s trust in Microsoft’s own security infrastructure. The attacker provides a code, and the victim, thinking they are just verifying their identity for Wi-Fi access, enters it on a genuine Microsoft page. Once that code is submitted, it can grant the attacker-controlled session access that is already satisfied by multi-factor authentication. It turns the user’s own security habits against them, transforming a robust defense like MFA into a bridge for the attacker to walk across. It is why we now strongly recommend that organizations block this specific flow through Conditional Access unless there is a documented and vital need for it.

What is your forecast for the security of hospitality networks and the evolution of these state-sponsored redirection campaigns?

I anticipate that hospitality networks will remain a primary battleground for high-value intelligence gathering because the underlying infrastructure—often managed by common third-party vendors—remains riddled with exposed management interfaces and weak credentials. We are seeing a “low-to-medium confidence” assessment that these simple entry points are exactly what Storm-2945 is exploiting to gain initial access. As long as these captive portal ecosystems share management systems, a single compromise can ripple across multiple venues globally. In the coming year, we will likely see these actors refine their “ClickFix” instructions to be even more convincing, perhaps even using AI-generated voice or video prompts to guide victims through terminal commands. For travelers, the only real defense is a shift in mindset: treat every public gateway as a hostile environment, use an always-on, full-tunnel VPN to bypass local DNS resolvers entirely, and never, under any circumstances, accept a software update or security certificate offered by a hotel portal.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later