
Storm-2945's 'CaptiveCrunch' Campaign Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT
A sophisticated espionage operation, 'CaptiveCrunch,' is targeting high-value travelers by hijacking hotel Wi-Fi to deliver the 'CornFlake' RAT. The campaign, attributed to Storm-2945, focuses on exfiltrating sensitive audio and visual data from corporate and diplomatic targets.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
In the last 48 hours, intelligence reports from Microsoft MSTIC and Mandiant have detailed a high-precision cyber espionage campaign dubbed 'CaptiveCrunch.' This operation, orchestrated by the threat actor Storm-2945, leverages compromised hotel network infrastructure to target traveling executives and government officials. By intercepting traffic at the captive portal level, the attackers deliver a sophisticated Remote Access Trojan (RAT) known as 'CornFlake.' This campaign highlights a renewed focus on 'on-the-road' intelligence gathering, targeting individuals during vulnerable transit periods where traditional corporate perimeter defenses are absent.
Threat Analysis
The 'CaptiveCrunch' campaign is characterized by its surgical targeting. Unlike broad-spectrum malware campaigns, Storm-2945 appears to monitor hotel reservation systems or local network traffic to identify specific high-value targets. Once a target is identified, the actor hijacks the hotel's Wi-Fi authentication page (captive portal) to serve a 'Critical Browser Update' notification. According to The Hacker News, this fake update serves as the initial access vector for the CornFlake malware. This tactic exploits the inherent trust users place in local network prompts while traveling, bypassing standard phishing filters that would typically catch such lures in an email environment.
Technical Details
The primary payload, CornFlake, is a modular RAT designed for deep surveillance. Technical analysis indicates that the malware can capture real-time microphone audio, webcam images, and keystrokes. A notable development in this campaign is the use of AI-assisted scripting. Recent reports from Mastodon's cybersecurity community suggest that China-aligned APTs, including those with TTPs overlapping with Storm-2945, are now utilizing public AI tools like Claude Code and DeepSeek to generate obfuscated PowerShell scripts. These scripts are used in the 'CaptiveCrunch' operation to automate post-exploitation tasks and maintain persistence. The malware communicates with its Command and Control (C2) infrastructure using HTTPS, frequently masquerading its traffic as legitimate telemetry data to evade network-based detection.
Attribution Assessment
Microsoft attributes this activity to Storm-2945 with high confidence. While the group's broader affiliations are still being mapped, the targeting of semiconductor industry leaders and maritime policy experts aligns with the strategic interests of East Asian nation-states. The sophistication of the infrastructure hijacking and the use of custom-built surveillance tools like CornFlake suggest a well-resourced, state-sponsored entity. There are also emerging indicators of collaboration between espionage groups and ransomware actors, a trend noted by Bank Info Security, where ransomware is used as a 'smokescreen' to hide the true intent of data exfiltration.
Implications
The 'CaptiveCrunch' operation poses a severe risk to corporate intellectual property and diplomatic confidentiality. By compromising targets in international business hubs, Storm-2945 gains access to sensitive negotiations and strategic planning sessions that occur outside the safety of secure office environments. The integration of AI tools for rapid script generation suggests that the actor can adapt to defensive measures faster than previously observed, making traditional signature-based detection increasingly ineffective.
Recommendations
To mitigate the risk of 'CaptiveCrunch' and similar hospitality-based threats, Encrygma recommends the following: 1. Enforce the use of Always-On VPNs for all traveling staff to encrypt traffic from the point of origin. 2. Implement strict EDR (Endpoint Detection and Response) policies that block unsigned executable downloads from non-standard domains. 3. Educate high-value targets on the risks of 'captive portal' updates and encourage the use of mobile hotspots over public Wi-Fi. 4. Monitor for unusual PowerShell activity or unauthorized use of AI-assisted coding tools within the corporate environment.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian-Linked 'Nimbus Manticore' Expands Espionage Arsenal with Advanced Backdoors

Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing

