Midnight Blizzard Uses Captive Portals to Deliver CornFlake RAT and Steal Traveler Credentials

Storm-2945, a Midnight Blizzard subcluster, has resumed CaptiveCrunch, an espionage campaign abusing hospitality Wi-Fi networks to infect travelers and compromise corporate accounts. An October 5, 2026 update confirms renewed activity observed on September 29, including deployment of a Rust variant of the CornFlake infostealer, with characteristics consistent with continued AI-enabled malware development. The resurgence likely […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: