Threat Advisory

Storm-2945 Deploys New CornFlake RAT Malware

Threat: Malware Campaign
Threat Actor Name: Midnight Blizzard
Threat Actor Type: State-sponsored
Targeted Region: Global
Threat Actor Region: Russia
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Russia-based threat actor Midnight Blizzard is conducting a campaign named CaptiveCrunch to steal credentials and sensitive data from corporate travelers. This operation primarily targets the hospitality sector across multiple countries by compromising captive portal networks found in hotels and conference centers. The attackers manipulate network traffic to redirect users to fraudulent sites, aiming to harvest authentication tokens and session cookies. Their ultimate goal is long-term espionage and intelligence gathering in support of foreign policy interests, specifically focusing on high-value corporate and government targets while they are away from their secure office environments.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Russia-based threat actor Midnight Blizzard is conducting a campaign named CaptiveCrunch to steal credentials and sensitive data from corporate travelers. This operation primarily targets the hospitality sector across multiple countries by compromising captive portal networks found in hotels and conference centers. The attackers manipulate network traffic to redirect users to fraudulent sites, aiming to harvest authentication tokens and session cookies. Their ultimate goal is long-term espionage and intelligence gathering in support of foreign policy interests, specifically focusing on high-value corporate and government targets while they are away from their secure office environments.[emaillocker id="1283"]

Attackers gain access by manipulating DNS and HTTP traffic on compromised Wi-Fi networks to intercept connection attempts. Victims encounter deceptive prompts mimicking legitimate system updates that trick them into manually downloading and executing malicious software. Once installed, a remote access trojan establishes persistence by registering as a system service and creating registry keys to ensure survival. This malware enables the theft of stored passwords, keystrokes, and files.

The group also uses adversary-in-the-middle techniques to intercept authentication flows, granting them ongoing access to cloud accounts without needing direct credentials. This threat poses significant risk because it bypasses email security filters by exploiting network infrastructure rather than relying on phishing messages. Corporate travelers are especially vulnerable when using public Wi-Fi, as the attack appears to be a standard system update. Detecting these intrusions is difficult due to the use of encrypted traffic and legitimate-looking processes. Organizations should warn employees about the risks of public networks and enforce the use of virtual private networks. Additionally, maintaining offline backups, applying security patches promptly, and monitoring for suspicious service registrations are critical steps to mitigate the risk of compromise.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Initial Access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1543.003 Create or Modify System Process Windows Service
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defense Evasion T1562.001 Impair Defenses Disable or Modify Tools
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Credential Access T1552.001 Unsecured Credentials Credentials In Files
Discovery T1082 System Information Discovery
Command and Control T1573.002 Encrypted Channel Asymmetric Cryptography
Command and Control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel

 

MBC MAPPING:No MBC Mapping content found in HTML.

REFERENCES:

reports contain further technical details:
https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/
https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/

[/emaillocker]
crossmenu