Hijacked Hotel Wi-Fi Delivers Surveillance Malware via Fake Updates
Microsoft has disclosed a cyberattack campaign in which threat actors hijacked hotel Wi-Fi networks to serve fake browser updates that deliver CornFlake, a remote access trojan (RAT). The malware is capable of capturing webcam images, microphone audio, and keystrokes, enabling extensive surveillance of victims. The attack likely targets business travelers and other high-value individuals staying at hotels, exploiting the trust users place in hotel internet connections. Microsoft's threat intelligence team identified the campaign and has provided technical details to help organizations and individuals defend against it. The attack underscores the growing sophistication of supply-chain and network-level compromises, where legitimate infrastructure is weaponized to distribute malware. No specific hotel chain or geographic region has been publicly named, but the implications for corporate espionage and data theft are significant.
Global Impact
This campaign has significant implications for cybersecurity, corporate espionage, and the hospitality industry. Economically, it threatens the confidentiality of business travelers, potentially leading to intellectual property theft and financial losses for affected companies.
Why this score
Neat Digest rated this story 3.5/10 — Standard tier.
This is a targeted cyberattack campaign with real espionage implications, but it is not a mass-casualty or civilization-level event; it fits the Significant tier due to its novel attack vector and potential for widespread corporate data breaches, though the scope is limited to hotel Wi-Fi users.
Sources on this story
Reported by 1 sources, including:
- The Hacker News