A new cyber-espionage campaign named 'CaptiveCrunch', attributed to the Russian hacking group Midnight Blizzard (also known as APT29), targets travelers by hijacking captive portals on hotel and conference Wi-Fi networks. This attack serves fake updates that install Russian espionage malware, specifically a remote access trojan (RAT) named CornFlake. The campaign, ongoing since early May 2026, exploits connectivity checks to deploy malware, posing as legitimate software updates.
Microsoft's investigation revealed vulnerabilities in shared services within the captive portal ecosystem. Recommendations include treating public Wi-Fi as untrustworthy and avoiding installations from captive portals.