The technique is more convincing than it sounds. When guests connect to hotel Wi-Fi, they are typically greeted by a captive portal, the login page that asks you to accept terms before granting internet access. In the CaptiveCrunch campaign, attackers who had already gained control of the network's gateway were able to intercept that process and redirect travelers to pages impersonating legitimate browser or operating system updates. Visitors who followed the prompts and ran the supplied commands unknowingly installed a piece of malware called CornFlake on their own devices.
CornFlake is a remote access trojan, or RAT, which is a type of malware that gives an attacker hidden, ongoing control over an infected machine. Once installed, it disguises itself as a routine Windows background process called "Cloud Sync Service" to avoid suspicion. While a fake progress bar keeps the victim occupied, CornFlake quietly gets to work. The malware can capture webcam images, record audio from the microphone, log keystrokes, steal saved passwords and browser cookies, and give attackers a live remote connection into the device.
A Threat That Bypasses Passwords and MFA
What makes this campaign particularly concerning is a tactic Microsoft observed beginning in mid-July. Some of the fake landing pages were redirecting hotel guests into a legitimate Microsoft sign-in flow, then prompting them to enter an attacker-supplied authentication code. Because this happens on Microsoft's own sign-in page, multi-factor authentication (MFA) does not block it. The victim essentially hands the attacker a fully authenticated session without realizing it. Researchers also identified a second malware tool called ChocoShell, which specifically targets Microsoft 365 and Azure tokens stored on the device, allowing attackers to access corporate accounts without needing a password at all.
Microsoft noted a detail that raises broader concerns: several of the affected hospitality networks shared common equipment and management infrastructure. This suggests the attackers may not have been targeting individual hotels one by one, but could have accessed systems that connect multiple venues through shared services. The full scope of affected locations has not been disclosed.
The initial method the attackers used to gain control of the hotel networks is still under v b investigation. Security firm ReliaQuest, which independently documented overlapping infrastructure eight days before Microsoft's report, assessed with low-to-medium confidence that exposed management interfaces combined with weak or reused administrator passwords may have been the entry point.
What Travelers Should Do Right Now
This campaign does not exploit some obscure technical flaw that only security experts can understand. It relies on a traveler trusting a prompt they see on a hotel's Wi-Fi page. That means the most effective defense is behavioral.
Use a corporate VPN that is configured to turn on automatically, before any Wi-Fi login occurs, routing your traffic through your organization's own network before the hotel gateway can interfere.
Reject any software update, browser extension, security certificate, or troubleshooting tool that appears on a captive portal login page, because legitimate networks do not require these.
Treat hotel and public Wi-Fi as untrusted networks regardless of how professional the login page looks, and avoid accessing sensitive corporate accounts without a VPN active.
Microsoft recommends that organizations restrict the device code authentication flow in Microsoft Entra (formerly Azure AD) Conditional Access policies wherever it is not operationally necessary. This closes the window the attackers have been exploiting since July.
The attack described here requires the victim to take an action, whether that is running a command, downloading a file, or entering a code. Employee awareness is a real layer of defense. Organizations whose teams travel regularly should ensure those employees know what legitimate hotel Wi-Fi looks like, and more importantly, what it does not look like.
How We Protect Our Clients
InfoPathways actively manages NordLayer corporate VPN for our clients as a frontline defense against exactly this type of attack. NordLayer is configured to activate automatically when a device connects to any network outside the office, meaning your traffic is routed through a secure, encrypted tunnel before the hotel or venue's gateway ever has a chance to intercept it. This effectively neutralizes the DNS manipulation technique at the core of the CaptiveCrunch campaign. If you are an existing InfoPathways client and have questions about your NordLayer configuration, or if your organization does not yet have a managed corporate VPN in place, contact us today to get protected before your next trip.