Midnight Blizzard Uses Captive Portals to Deliver CornFlake RAT and Steal Traveler Credentials

A Midnight Blizzard subcluster (Storm-2945) has resumed CaptiveCrunch, an espionage campaign abusing hospitality Wi-Fi captive portals to infect travelers and compromise corporate accounts. Renewed activity observed September 29 includes a Rust variant of the CornFlake infostealer, with indicators consistent with AI-enabled malware development.

Source: gbhackers.com

Curated Permalink