CornFlake is a Go-based Windows remote access trojan used as the primary persistent implant in the CaptiveCrunch espionage campaign attributed by Microsoft to Storm-2945, a sub-cluster of Midnight Blizzard (APT29), which Western governments have linked to Russia’s SVR. It is designed to provide long-term access to compromised Windows systems and to support credential theft, surveillance, reconnaissance, and data exfiltration against targets that appear to include corporate travelers and organizations of intelligence interest.
CornFlake has been delivered through captive-portal traffic manipulation on hospitality and conference Wi-Fi networks, where victims are redirected to fake browser or operating system update pages using ClickFix-style social engineering. During installation it displays a fake progress or update window to reduce suspicion, then establishes durable persistence through multiple mechanisms including Windows service registration, Run-key persistence, scheduled tasks, and a watchdog routine that restores removed persistence components. It masquerades as a legitimate cloud synchronization service to blend into the host environment.
The malware supports a broad post-compromise feature set. Reported capabilities include remote shell access, keylogging, clipboard monitoring, screenshot capture, microphone and webcam surveillance, browser credential theft, cookie theft, Microsoft 365 session token theft, file exfiltration, USB monitoring, and host reconnaissance. It also collects system intelligence and supports encrypted command-and-control communications using modern cryptographic key exchange. Some reporting indicates it exposes a local HTTP API that can support modular tasking and companion payloads such as ChocoShell.
Operationally, CornFlake functions as the persistence and remote-control component of a broader intrusion set that also includes ChocoShell, an in-memory PowerShell stealer, and FruitStone, a web-based management panel. The malware is associated with espionage-oriented collection rather than disruptive effects, with emphasis on maintaining access, harvesting credentials and sessions, monitoring victim activity, and extracting files and other sensitive data from Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware.
Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware.
One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.
One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
Additional defense evasion and privilege abuse across the toolset include SYSTEM token impersonation
In dropper mode, CornFlake displays a fake progress window while copying itself to %APPDATA%\svchost32\svchost32.exe.
Additional defense evasion and privilege abuse across the toolset include ... Volume Shadow Copy Service abuse
Additional defense evasion and privilege abuse across the toolset include SYSTEM token impersonation, Volume Shadow Copy Service abuse
It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell... ChocoShell runs entirely in memory... harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials.
After compromising captive portal equipment or shared infrastructure, Storm-2945 manipulates DNS and HTTP traffic on the network. When a victim connects to Wi-Fi and encounters the captive portal login prompt, traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure
Microsoft also discovered an unprotected web-based management panel, FruitStone, which the threat actor used to manage infected systems, browse victim files, execute PowerShell commands, and capture screenshots and keystrokes.
It establishes an encrypted C2 channel via ECDH P-256 key exchange and provides RAT capabilities including keylogging, screenshot capture
CornFlake is a Go-based remote access trojan with a broad capability set: remote shell access, keylogging, clipboard monitoring, screenshot capturing, microphone and webcam surveillance...
It establishes an encrypted C2 channel via ECDH P-256 key exchange and provides RAT capabilities including keylogging, screenshot capture, microphone and webcam surveillance
provides RAT capabilities including keylogging, screenshot capture, microphone and webcam surveillance
After compromising captive portal equipment or shared infrastructure, Storm-2945 manipulates DNS and HTTP traffic on the network. When a victim connects to Wi-Fi and encounters the captive portal login prompt, traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure
Collected data is compressed, encoded, and exfiltrated via HTTPS POST to C2 endpoints disguised as tracking pixels and JavaScript polyfill files.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware developed and used in support of the CaptiveCrunch credential theft campaign; the content ties it to harvesting credentials and malware delivery but does not provide deeper technical detail.
A Go-based Windows remote access trojan used for persistent access. It copies itself to %APPDATA%\svchost32\svchost32.exe, establishes an encrypted C2 channel via ECDH P-256, and supports keylogging, screenshot capture, microphone and webcam surveillance, file exfiltration, USB monitoring, and remote shell execution. It also implements persistence via services, Registry Run keys, scheduled tasks, and a watchdog routine.
A Go-based Windows remote access trojan used for persistent access. It establishes encrypted C2 via ECDH P-256 and supports keylogging, screenshot capture, microphone and webcam surveillance, file exfiltration, USB monitoring, and remote shell execution. It also implements persistence through services, Registry Run keys, scheduled tasks, and a watchdog routine.
A Go-based remote access trojan used for persistent access, credential theft, surveillance, and data exfiltration. It supports remote shell access, keylogging, clipboard and screenshot capture, microphone/webcam surveillance, browser credential and cookie theft, Microsoft 365 session token theft, USB monitoring, and reconnaissance. It persists via Windows services, registry run keys, scheduled tasks, and a watchdog routine, while disguising itself with fake progress/update windows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.