Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
What happened
The threat actor Storm-2945, a sub-cluster of Midnight Blizzard, is using hijacked hotel Wi-Fi to deliver CornFlake remote access trojans via fake browser updates. The malware enables attackers to capture webcam images, microphone audio, and keystrokes from infected devices.
Why it ranks #1
This represents an active campaign by a known sophisticated state-sponsored actor (Midnight Blizzard) using social engineering and infrastructure hijacking for immediate enterprise exposure during travel.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Advise employees to avoid installing browser updates over public Wi-Fi and utilize corporate VPNs.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed