Attackers are abusing compromised hotel and conference-center Wi-Fi systems to push fake software updates that install CornFlake, a remote access trojan tied to surveillance activity. The campaign reportedly targets guests after they connect to affected networks, turning a routine internet login into a malware delivery path.
The method centers on control of DNS and captive portal infrastructure. Instead of sending users to a normal sign-in or access page, the hijacked gateway can redirect them to convincing prompts that claim a browser or operating-system update is required. If a victim follows the prompt, the download delivers malicious software rather than a legitimate update.
CornFlake is described as a surveillance-focused RAT, meaning it is designed to give attackers remote access and visibility into a compromised device. Microsoft has attributed the malware family to Storm-2945, linking the operation to a known threat actor rather than a random opportunistic scam.
The case highlights how public and semi-public Wi-Fi environments can become high-risk points of infection when network equipment is tampered with. Hotels and conference venues are especially attractive because travelers often expect captive portals, software prompts, and unfamiliar login pages, making fake update screens easier to disguise as normal network behavior.