Microsoft has linked a cyberattack campaign to hijacked hotel Wi-Fi networks that push fake browser updates to unsuspecting travelers. Instead of delivering legitimate software, the bogus update installs CornFlake, a remote access trojan designed to quietly take control of infected devices.
The malware’s capabilities make it especially invasive. Based on Microsoft’s findings, CornFlake can capture webcam images, record microphone audio, and log keystrokes, giving attackers a way to monitor victims and gather sensitive information from compromised laptops.
The campaign also goes beyond local device spying. The report says the attackers seek to steal cloud authentication tokens and abuse device code sign-in flows, a tactic that can help them access online accounts even after a victim leaves the hotel network. That suggests the operation is aimed not just at immediate surveillance, but also at longer-term account compromise.
The use of hotel Wi-Fi as the delivery path highlights the risks travelers face when relying on public internet connections. By disguising malware as a routine browser update, the attackers appear to be using a familiar prompt to lower suspicion and increase the chances that a target installs the malicious software.