APT29 Hijack Hotel Wi-Fi to Steal Credentials with CornFlake and CocoShell
> cd .. / HUB_EDITORIALE
News

APT29 Hijack Hotel Wi-Fi to Steal Credentials with CornFlake and CocoShell

[2026-08-04] Author: Ing. Calogero Bono
> share
Zenithby Meteora Web The operating system for your business. Social, clients, bookings and invoices in one platform. Gyms, barbers, professionals. Discover Zenith Free demo · no card

Researchers at Microsoft have published a new report detailing how Russian state-sponsored actors, known as Midnight Blizzard or APT29, are attacking captive portal equipment in hotels and conference centers. These portals are the networking hardware and software that manage the login page users see before accessing public Wi-Fi. When connecting to a hotel network, users are often redirected to a page where they must enter their room number, accept the terms of service, and click Connect. It is this redirection that attackers are exploiting.

The Attack Mechanism and Fake Microsoft 365 Pages

Microsoft did not explain exactly how this gear is attacked, but they described what happens when users try to log in on compromised networks. They may be redirected to a fake Microsoft 365 login portal that steals their credentials. Alternatively, they could end up on device code phishing pages abusing Microsoft Entra ID authentication flows. The researchers also observed the captive portals being used to display fake browser and OS update pages that trick victims into downloading infostealers.

Sponsored Protocol

CornFlake and CocoShell Malware Variants Distributed

So far, Microsoft has identified two malware variants distributed through these attacks. The first, named CornFlake, acts as an infostealer capable of grabbing keystrokes and clipboard, running remote shell access, grabbing screenshots, using the microphone and webcam, stealing browser credentials and cookies, exfiltrating files, and more. It presents itself as a "Cloud Sync Service" while using multiple persistence mechanisms. The second, CocoShell, is an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.

Sponsored Protocol

These attacks are not only a concern for travelers but also for those attending conferences and events in convention centers, where the use of public Wi-Fi networks is common. The compromise of captive portals represents an insidious threat because the user thinks they are connecting to a legitimate network, while in reality they are handing over their credentials to cybercriminals. To protect themselves, experts advise avoiding entering corporate credentials on public Wi-Fi networks, using a reliable VPN, and keeping devices updated. Additionally, it is crucial to pay attention to the URLs of login pages and verify that the SSL certificate is valid.

This is not the first case of cyberattacks in hotel environments. Recently, there has been talk of how Google Clock 9.0 Extends Live Updates to Stopwatch and Timer, but cybersecurity remains a priority. For developers, secure log management is crucial, as illustrated in Structured JSON Logging. APT29 is one of the most documented state-sponsored actors, active for years and known for its links to Russia's Foreign Intelligence Service. It has conducted high-profile attacks against Western targets, including US and German government officials, and the SolarWinds and Microsoft campaigns. Awareness and proactive security measures are essential to mitigate these threats.

Sponsored Protocol

Source: https://www.techradar.com/pro/security/travelers-beware-microsoft-experts-warn-hotel-wi-fi-can-be-hijacked-to-infect-your-devices-with-dangerous-malware

> share
Ing. Calogero Bono

> AUTHOR_EXTRACTED

Ing. Calogero Bono

Ingegnere informatico, fondatore di Meteora Web e Zenith OS. System administrator e progettista di piattaforme, app e CMS proprietari, con esperienza in sviluppo full-stack, marketing digitale ed ecosistema Google.
[ Read Full Dossier ]

> METEORA_WEB // DIGITAL AGENCY

We build the digital presence your business deserves.

Websites, social media, online advertising, e-commerce and high-performance hosting, engineered with method by computer engineers in Sciacca, for all of Italy.

> MW_JOURNAL

> READ_ALL()