Microsoft recently put out a warning to travellers, saying their personal data and information may have been compromised by Russian hackers. Specifically, the Russian threat actors backed by the state have been targeting Wi-Fi networks at hotels and conferences all over the world.
CaptiveCrunch And No, It’s Not A Cereal
Microsoft named the operation CaptiveCrunch, presumably after the popular US cereal mascot, and that Russian hackers from the group Storm-2945 — which itself is a branch of Midnight Blizzard — have been targeting the networks of establishments within the hospitality industry. For the uninitiated, Midnight Blizzard is a group of black hat hackers, believed to have links to Russia’s Foreign Intelligence Service (SVR).

“Since February 2026, Storm-2945 has conducted AI-augmented operations including targeted device code and OAuth code phishing campaigns leading to Entra device registration and subsequent data collection from Microsoft 365. Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem.”
The attacks aren’t just limited to Windows devices either. Microsoft states in its blog that the hackers may also be targeting Android users, using similar techniques like the ClickFix landings, including “instructions” for Android devices to download and install the offending APK file.
Tools Of The Trade

One of the tools used by the Russian hackers is a program called CornFlake. As per Microsoft’s explanation: “CornFlake is a full-featured Windows RAT written in Go that serves as Storm-2945’s primary persistent implant. Microsoft has observed the threat actor rapidly iterating on this malware layer, which features customizable capabilities from the social engineering user interface and data collection capabilities to anti-detection and evasion techniques. On initial execution, CornFlake operates in dropper mode: it displays a convincing fake progress window designed to occupy the victim’s attention while the binary copies itself to %APPDATA%\svchost32\svchost32.exe and establishes persistence.”
To cut a long story short, CornFlake can be used to create fake options that look legit, including winupdate, defender, directx, vcredist, sysopt, and netfix, to name a few. If that wasn’t bad enough, Microsoft also says that the hackers have leveraged AI in helping with their endeavours.
If you’re travelling, it is considered best practice to never conduct any form of updates on Windows through an unsecured connection, most especially through a hotel network.
(Source: Microsoft, Techspot, ReliaQuest)

