Microsoft Threat Intelligence identifies Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread captive portal traffic manipulation attacks since May 2026 targeting travelers at hospitality venues worldwide. The campaign delivers CornFlake, a Go-based Windows RAT with comprehensive surveillance and credential theft capabilities, and ChocoShell, a PowerShell-based infostealer that bypasses AMSI, employs multiple UAC bypass techniques, and extracts browser credentials via Chrome DevTools Protocol to circumvent Chrome App-Bound Encryption. The operation also integrates device code phishing against Microsoft Entra ID, leveraging AI-augmented social engineering and ClickFix techniques to maximize victim compliance.
CornFlake RAT
1 post
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft