Midnight Blizzard Uses Captive Portals to Deliver CornFlake RAT and Steal Traveler Credentials
A Midnight Blizzard subcluster (Storm-2945) has resumed CaptiveCrunch, an espionage campaign abusing hospitality Wi-Fi captive portals to infect travelers and compromise corporate accounts. Renewed activity observed September 29 includes a Rust variant of the CornFlake infostealer, with indicators consistent with AI-enabled malware development.