Russia-nexus actors

1 items · Attacks 1 · all entities

A Russia-linked crew compromised hotel Wi-Fi captive portals, with malware Microsoft assesses was largely AI-built

Zscaler ThreatLabz reports Storm-2945, a sub-cluster of Midnight Blizzard, compromising shared captive portal services used by hotels and conference centres to harvest Microsoft 365 credentials and deploy the CornFlake Go remote access trojan and the ChocoShell PowerShell stealer, with compromised gateways identified in several US cities, India and Saudi Arabia. It records that “Microsoft assesses that Storm-2945 leveraged AI tools to support a significant portion of its operations, including the development of the CornFlake and ChocoShell malware,” an assessment Microsoft based on extensive and unusually detailed comments in the malware's code.

Reported by researchersZscaler ThreatLabz ↗ ·