CaptiveCrunch
Coverage of CaptiveCrunch in the Nexus archive.
- Travelers targeted when logging into hotel Wi-Fi networks
Microsoft has warned that a Russian group is exploiting hotel and hospitality Wi-Fi networks to target travelers via DNS and HTTP traffic manipulation. The campaign, named 'CaptiveCrunch,' uses phishing pages, malware like CornFlake and ChocoShell, and fake system update prompts to steal credentials and compromise devices. Malwarebytes advises using personal hotspots or VPNs with Kill Switch features to mitigate risks.
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update distributed via hijacked hotel Wi-Fi is delivering CornFlake, a remote access trojan (RAT) capable of capturing webcam images, microphone audio, and keystrokes. Microsoft attributes the operation, tracked as CaptiveCrunch, to Storm-2945, which is linked to the Midnight Blizzard group.