INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hotel Wi-Fi attacks use custom malware to breach Microsoft
| 2026-08-04 00:17 CRITICAL HIGH DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A global campaign targeting hospitality Wi-Fi networks, attributed to the Russian threat actor Midnight Blizzard (also known as APT29), has been linked by Microsoft since at least early May 2026. The attackers manipulate DNS and HTTP traffic on captive portal equipment, allowing them to intercept user connections to hotel and conference center Wi-Fi networks. They then redirect victims to phishing pages impersonating Microsoft 365 login portals or device code phishing pages abusing Microsoft Entra ID authentication flows. Additionally, they use fake browser and operating system update pages that deliver malware to Windows via ClickFix prompts for user verification. The campaign has been active since at least July 2026, with evidence of breaches in shared infrastructure rather than isolated devices. Two malware families, CornFlake and ChocoShell, have been identified by Microsoft, offering capabilities such as persistent access, credential theft, surveillance, and data exfiltration.
Technical Mitigations AI-generated
• Block or hunt for ChocoShell malware by disabling browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.
• Use a private cellular connection instead of hotel conference center Wi-Fi networks to prevent DNS manipulation attacks.
• Disable device code authentication with MFA when not needed to reduce the risk of OAuth code phishing operations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT29APT29
Target & Sectors
Global Scope
healthhealth
hospitalityhospitality
Incident Timeline
2026/08/04
Threat actors used custom malware, including CornFlake and ChocoShell, to target Microsoft 365 accounts via compromised hotel Wi-Fi networks.
Click on any entity below to view its context and source!
threat_actor
APT29
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.
infrastructure
Microsoft 365
After modifying DNS settings, the attacker can redirect victims to phishing pages that impersonate Microsoft 365 login portals, or to device code phishing pages that abuse Microsoft Entra ID authentication flows.
…Clipboard monitoring
Screenshot capturing
Microphone and webcam surveillance
Browser credential and cookie theft
Microsoft 365 session token theft
File exfiltration
USB monitoring
System reconnaissance
When executed, CornFlake sh…
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts.
The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker
changed DNS settings
on Wi-Fi devices to steal Microsoft 365 accounts.
The second payload, ChocoShell, is an in-memory PowerShell credential stealer that targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.
infrastructure
Windows
CornFlake and ChocoShell malware
Microsoft analyzed the two new Windows malware families and found that CornFlake is a Go-based remote access trojan (RAT) that offers the following capabilities:
Remote shell access
Keylogging
Clipboard moni…
A third option not previously disclosed involves using fake browser and operating system update pages that deliver malware to Windows via ClickFix prompts for user verification.
According to the researchers, the bogus window can be configured to appear as a Windows update screen, a Defender virus scan, a disk optimization utility, a network diagnostics tool, a browser update prompt, or a document viewer installer.
Fake Windows update
Source: Microsoft
CornFlake disguises itself as “Cloud Sync Service” to appear as a legitimate Windows component, and uses multiple persistence mechanisms on the host, including Windows service registrations, registry run keys…
infrastructure
Android
ClickFix prompt in CaptiveCrunch campaign
source: Microsoft
Microsoft also found evidence in some ClickFix landings indicating that the threat actor is also targeting Android devices to deliver an APK file.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
After modifying DNS settings, the attacker can redirect victims to phishing pages that impersonate Microsoft 365 login portals, or to device code phishing pages that abuse Microsoft Entra ID authentication flows.
…Clipboard monitoring
Screenshot capturing
Microphone and webcam surveillance
Browser credential and cookie theft
Microsoft 365 session token theft
File exfiltration
USB monitoring
System reconnaissance
When executed, CornFlake sh…
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts.
The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker
changed DNS settings
on Wi-Fi devices to steal Microsoft 365 accounts.
The second payload, ChocoShell, is an in-memory PowerShell credential stealer that targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.
Metrics
infrastructure
Windows
Affected Product
CornFlake and ChocoShell malware
Microsoft analyzed the two new Windows malware families and found that CornFlake is a Go-based remote access trojan (RAT) that offers the following capabilities:
Remote shell access
Keylogging
Clipboard moni…
A third option not previously disclosed involves using fake browser and operating system update pages that deliver malware to Windows via ClickFix prompts for user verification.
According to the researchers, the bogus window can be configured to appear as a Windows update screen, a Defender virus scan, a disk optimization utility, a network diagnostics tool, a browser update prompt, or a document viewer installer.
Fake Windows update
Source: Microsoft
CornFlake disguises itself as “Cloud Sync Service” to appear as a legitimate Windows component, and uses multiple persistence mechanisms on the host, including Windows service registrations, registry run keys…
Metrics
infrastructure
Android
Affected Product
ClickFix prompt in CaptiveCrunch campaign
source: Microsoft
Microsoft also found evidence in some ClickFix landings indicating that the threat actor is also targeting Android devices to deliver an APK file.
Intelligence Sources
BleepingComputer
2026-08-04
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:11
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
CornFlake
entity
5x
tactic
Cyber Operation Type
Exfiltration
tactic
3x
infrastructure
Affected Product
Microsoft 365
software
2x
tactic
MITRE ATT&CK Technique
T1056.001 - Keylogging
technique
2x
general metric
%
54
%
Contextual Telemetry
Context Block
4 METRICS
source region
Origin Country
Russian Federation
country
industry
Targeted Sector
Hospitality
sector
threat actor
APT Group
APT29
actor
general metric
Microsoft
365
microsoft
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.