Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Summary
Hackers have hijacked hotel Wi-Fi networks to push fake browser updates, installing a surveillance malware called CornFlake. This malware, tracked as CaptiveCrunch and attributed to Storm-2945, can steal webcam images, microphone audio, and keystrokes.
IFF Assessment
FOE
This article details a new method of malware distribution that compromises user devices and steals sensitive information, representing a significant threat to defenders.
Defender Context
This incident highlights the risks associated with public Wi-Fi networks, particularly in hospitality settings. Defenders should advise users to avoid public Wi-Fi for sensitive activities and to ensure their devices have robust endpoint protection and up-to-date security software.