News Room
16
Share
Midnight Blizzard Targets Global Hospitality Networks with CornFlake and ChocoShell Malware
highThreat Intelligence

Midnight Blizzard Targets Global Hospitality Networks with CornFlake and ChocoShell Malware

Russian-linked threat actor Midnight Blizzard (APT29) is actively compromising hotel Wi-Fi networks to hijack Microsoft 365 credentials. The campaign utilizes custom malware families, CornFlake and ChocoShell, to maintain persistence and exfiltrate sensitive corporate data.

11 August 2026Last updated 18 August 20264 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
Nation-State
Geography:
Global
Confidence:
High Confidence
Source:
Microsoft MSTIC
Read Time:
4 min

Executive Summary

In early August 2026, security researchers identified a sophisticated global campaign targeting hospitality Wi-Fi networks. Attributed to the Russian state-sponsored actor Midnight Blizzard (also known as APT29 or Storm-2945), the operation focuses on intercepting network traffic to compromise Microsoft 365 accounts. By manipulating DNS settings on hotel captive portal equipment, the attackers gain a foothold in the networks of traveling business professionals and government officials.

Threat Analysis

The campaign represents a strategic shift toward exploiting the 'trusted' environment of hotel networks. Rather than traditional phishing, the attackers perform man-in-the-middle (MitM) attacks at the network infrastructure level. By hijacking DNS and HTTP traffic, the threat actors can redirect users to malicious login portals or inject payloads directly into active sessions, effectively bypassing standard perimeter defenses.

Technical Details

The operation relies on two primary custom malware families: CornFlake and ChocoShell.

  • CornFlake: A specialized implant designed for initial network reconnaissance and DNS manipulation. It allows the actor to intercept and modify traffic flowing through compromised hotel gateways.
  • ChocoShell: A modular backdoor used for persistent access and credential theft. Once a user is redirected, ChocoShell facilitates the exfiltration of session tokens and authentication data, enabling the attackers to gain unauthorized access to Microsoft 365 environments without triggering standard multi-factor authentication (MFA) alerts.

Attribution Assessment

Microsoft and other intelligence partners have high confidence in attributing this activity to Midnight Blizzard. The tactical overlap, specifically the use of sub-cluster Storm-2945, aligns with previously observed TTPs (Tactics, Techniques, and Procedures) used by the group in high-profile espionage campaigns. The focus on high-value targets within the hospitality sector suggests a clear intelligence-gathering objective.

Implications

This campaign poses a significant risk to organizations whose employees travel frequently. The ability to compromise cloud-based productivity suites via local network infrastructure renders traditional endpoint security insufficient. If successful, the attackers gain long-term access to internal communications, proprietary documents, and strategic planning data.

Recommendations

  1. Mandate VPN Usage: Enforce the use of corporate-managed VPNs for all employees, especially when connecting to public or hotel Wi-Fi networks.
  2. Zero Trust Architecture: Implement strict conditional access policies that require device health checks and location-based verification for M365 access.
  3. DNS Security: Utilize encrypted DNS (DoH/DoT) to prevent local network administrators or attackers from hijacking DNS queries.
  4. Credential Monitoring: Monitor for anomalous login patterns, particularly those originating from unexpected geographic locations or IP ranges associated with hospitality providers.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo