호텔 Wi-Fi 해킹으로 가짜 브라우저 업데이트가 악성코드를 유포하고 있다.
해킹된 호텔 Wi-Fi를 통해 제공된 가짜 브라우저 업데이트가 CornFlake라는 원격 접근 트로이 목마를 배포하고 있다. 이 악성코드는 웹캠 이미지, 마이크 오디오 및 키 입력을 캡처할 수 있다. 마이크로소프트는 이 공격을 CaptiveCrunch라는 이름으로 추적하고 있으며, Storm-2945에 기인한다고 분석하고 있다.
Hijacked hotel Wi-Fi serves fake updates delivering surveillance malware.
A fake browser update delivered over hijacked hotel Wi-Fi is used to spread CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. Microsoft attributes this operation to CaptiveCrunch and links it to Storm-2945, considered an operational sub-cluster of Midnight Blizzard.