CornFlake is a Windows remote access trojan used as the primary persistent implant in CaptiveCrunch, an espionage campaign attributed to Storm-2945, an operational sub-cluster of Midnight Blizzard (APT29). Midnight Blizzard is linked by US and UK authorities to Russia’s Foreign Intelligence Service. CornFlake is principally written in Go; a Rust variant was observed in September 2026.
The malware provides remote command execution, keylogging, clipboard monitoring, screenshot capture, microphone and webcam surveillance, browser password and cookie theft, Microsoft 365 session-token theft, file exfiltration, removable-media monitoring, and system and security-posture reconnaissance. It establishes encrypted command-and-control communications using ephemeral ECDH P-256 key exchange and a custom encrypted JSON protocol. A local HTTP API supports modular tasking and integration with companion payloads such as the ChocoShell information stealer. Operators manage implants through the FruitStone command-and-control panel.
During installation, CornFlake displays a deceptive update or maintenance progress window and masquerades as a legitimate cloud synchronization service. It maintains redundant persistence through Windows services, registry autorun entries, scheduled tasks, and a watchdog that restores removed persistence mechanisms.
CaptiveCrunch delivers CornFlake through fake browser or operating-system updates and ClickFix landing pages presented over compromised hotel, conference-center, and other captive-portal Wi-Fi networks. Attackers manipulate DNS and HTTP traffic to redirect connectivity checks to malicious pages, persuading victims to download or execute the payload. The operation targets corporate travelers across multiple sectors and countries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A principal implant, CornFlake, displays a false progress window while copying itself to an application-data folder and creating several ways to restart after reboot.
A principal implant, CornFlake, displays a false progress window while copying itself to an application-data folder and creating several ways to restart after reboot.
One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.
One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell
Victims are instructed to paste and run commands, in some cases with instructions for Android APK installation. Executing the ClickFix instructions downloads and runs CornFlake and/or ChocoShell.
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
Additional defense evasion and privilege abuse across the toolset include SYSTEM token impersonation
In dropper mode, CornFlake displays a fake progress window while copying itself to %APPDATA%\svchost32\svchost32.exe.
Additional defense evasion and privilege abuse across the toolset include ... Volume Shadow Copy Service abuse
Additional defense evasion and privilege abuse across the toolset include SYSTEM token impersonation, Volume Shadow Copy Service abuse
CornFlake ou des voleurs de données comme ChocoShell, capables de capturer les frappes au clavier...
It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell... ChocoShell runs entirely in memory... harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials.
After compromising captive portal equipment or shared infrastructure, Storm-2945 manipulates DNS and HTTP traffic on the network. When a victim connects to Wi-Fi and encounters the captive portal login prompt, traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure
CornFlake ou des voleurs de données comme ChocoShell, capables de capturer les frappes au clavier...
It establishes an encrypted C2 channel via ECDH P-256 key exchange and provides RAT capabilities including keylogging, screenshot capture
CornFlake is a Go-based remote access trojan with a broad capability set: remote shell access, keylogging, clipboard monitoring, screenshot capturing, microphone and webcam surveillance...
provides RAT capabilities including keylogging, screenshot capture, microphone and webcam surveillance
After compromising captive portal equipment or shared infrastructure, Storm-2945 manipulates DNS and HTTP traffic on the network. When a victim connects to Wi-Fi and encounters the captive portal login prompt, traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure
Collected data is compressed, encoded, and exfiltrated via HTTPS POST to C2 endpoints disguised as tracking pixels and JavaScript polyfill files.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows remote-access implant deployed in the CaptiveCrunch campaign through manipulated captive portals and deceptive update or ClickFix prompts. It displays fake installation progress, persists across reboots, and masquerades as a Windows service named Cloud Sync Service. Its executable is placed at %APPDATA%\svchost32\svchost32.exe. An October 5, 2026 update reported a Rust variant in renewed activity beginning September 29.
A remote-access implant deployed in the CaptiveCrunch campaign through manipulated captive portals and deceptive update or ClickFix prompts. It displays a fake progress window, copies itself into an application-data directory, establishes persistence, and masquerades as a Windows service named Cloud Sync Service. The report also describes a Rust variant observed during renewed campaign activity beginning September 29, 2026.
Trojan deployed through ClickFix-style social-engineering lures delivered after interception and redirection of hotel or conference Wi-Fi traffic.
Malware developed and used in support of the CaptiveCrunch credential theft campaign; the content ties it to harvesting credentials and malware delivery but does not provide deeper technical detail.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.