Russian Intelligence Group Hijacks Global Hotel Wi-Fi to Deploy Surveillance Malware
AI-generated from multiple sources. Verify before acting on this reporting.
MOSCOW — A cyberespionage campaign attributed to Russia's Foreign Intelligence Service (SVR) has compromised hotel Wi-Fi networks across multiple countries, using the infrastructure to distribute surveillance malware and steal sensitive data from travelers. The operation, identified by cybersecurity researchers as Storm-2945, exploited captive portal gateways at hospitality venues to serve fraudulent browser updates that installed remote access tools on guest devices.
The attack began in early August 2026, targeting the unsecured or poorly secured wireless networks common in hotels worldwide. Attackers manipulated these networks to intercept traffic and present users with fake update prompts when they attempted to connect to the internet. Once a user accepted the false update, their device was infected with two distinct pieces of malicious software: CornFlake, a Remote Access Trojan (RAT) designed for long-term surveillance, and ChocoShell, an information stealer capable of harvesting credentials, session cookies, and financial data.
Security experts indicate that Storm-2945 has been active across various international jurisdictions, taking advantage of the transient nature of hotel guests who often connect to public networks without adequate security measures. The campaign represents a sophisticated evolution in state-sponsored cyber operations, moving beyond simple network interception to direct device compromise through social engineering tactics embedded within the login process.
The CornFlake RAT allows operators to monitor keystrokes, capture screenshots, and access files on infected machines, while ChocoShell focuses specifically on extracting authentication tokens that could grant unauthorized access to email accounts, banking portals, and corporate systems. By embedding these tools in a fake browser update mechanism, the attackers bypassed standard security warnings that might otherwise alert users to suspicious downloads.
The scope of the intrusion remains partially unclear as investigators work to identify all affected properties and estimate the number of compromised devices. While no specific hotel chains have been publicly named by authorities, the widespread nature of the attack suggests a broad targeting strategy rather than isolated incidents against individual high-profile guests.
Cybersecurity firms are currently advising travelers to avoid connecting personal devices to public Wi-Fi networks in hospitality settings until further notice and to ensure all operating systems and browsers are fully patched. The incident highlights growing vulnerabilities in global travel infrastructure, where the convenience of free internet access creates a significant vector for state-sponsored espionage.
Questions remain regarding whether any specific government officials or corporate executives were targeted during this phase of the operation, as well as how long the malware has been active on infected devices before detection. Law enforcement agencies and intelligence communities are coordinating to trace the command-and-control servers used by Storm-2945 and determine if additional variants of the malware have already been deployed.