CornFlake is a Go-based remote access trojan (RAT) targeting Windows systems. It is assessed as Storm-2945’s primary persistent implant in the CaptiveCrunch espionage campaign, which has been linked to the Russia-aligned Midnight Blizzard (APT29) threat actor. The campaign targeted corporate travelers through compromised captive-portal infrastructure at hospitality and conference venues, using ClickFix-style fake browser or operating-system update lures to persuade victims to execute the malware. CornFlake presents a deceptive progress interface during installation and establishes redundant persistence through Windows services, Run-key entries, scheduled tasks, and a watchdog mechanism that can restore removed persistence. It communicates with command-and-control infrastructure through an encrypted channel and supports remote shell access, host reconnaissance, keylogging, clipboard monitoring, screenshot capture, microphone and webcam surveillance, browser credential and cookie theft, Microsoft 365 session-token theft, removable-media monitoring, and file exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware.
One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.
One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell
Victims are instructed to paste and run commands, in some cases with instructions for Android APK installation. Executing the ClickFix instructions downloads and runs CornFlake and/or ChocoShell.
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
CornFlake implements persistence through service registration, Registry Run keys, scheduled tasks, and a watchdog routine.
CornFlake disguises itself as "Cloud Sync Service" to appear legitimate and uses several persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine that restores any removed persistence method.
Additional defense evasion and privilege abuse across the toolset include SYSTEM token impersonation
In dropper mode, CornFlake displays a fake progress window while copying itself to %APPDATA%\svchost32\svchost32.exe.
Additional defense evasion and privilege abuse across the toolset include ... Volume Shadow Copy Service abuse
Additional defense evasion and privilege abuse across the toolset include SYSTEM token impersonation, Volume Shadow Copy Service abuse
CornFlake ou des voleurs de données comme ChocoShell, capables de capturer les frappes au clavier...
It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell... ChocoShell runs entirely in memory... harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials.
After compromising captive portal equipment or shared infrastructure, Storm-2945 manipulates DNS and HTTP traffic on the network. When a victim connects to Wi-Fi and encounters the captive portal login prompt, traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure
CornFlake ou des voleurs de données comme ChocoShell, capables de capturer les frappes au clavier...
It establishes an encrypted C2 channel via ECDH P-256 key exchange and provides RAT capabilities including keylogging, screenshot capture
CornFlake is a Go-based remote access trojan with a broad capability set: remote shell access, keylogging, clipboard monitoring, screenshot capturing, microphone and webcam surveillance...
provides RAT capabilities including keylogging, screenshot capture, microphone and webcam surveillance
After compromising captive portal equipment or shared infrastructure, Storm-2945 manipulates DNS and HTTP traffic on the network. When a victim connects to Wi-Fi and encounters the captive portal login prompt, traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure
Collected data is compressed, encoded, and exfiltrated via HTTPS POST to C2 endpoints disguised as tracking pixels and JavaScript polyfill files.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan deployed through ClickFix-style social-engineering lures delivered after interception and redirection of hotel or conference Wi-Fi traffic.
Malware developed and used in support of the CaptiveCrunch credential theft campaign; the content ties it to harvesting credentials and malware delivery but does not provide deeper technical detail.
A Go-based Windows remote access trojan used for persistent access. It copies itself to %APPDATA%\svchost32\svchost32.exe, establishes an encrypted C2 channel via ECDH P-256, and supports keylogging, screenshot capture, microphone and webcam surveillance, file exfiltration, USB monitoring, and remote shell execution. It also implements persistence via services, Registry Run keys, scheduled tasks, and a watchdog routine.
A Go-based Windows remote access trojan used for persistent access. It establishes encrypted C2 via ECDH P-256 and supports keylogging, screenshot capture, microphone and webcam surveillance, file exfiltration, USB monitoring, and remote shell execution. It also implements persistence through services, Registry Run keys, scheduled tasks, and a watchdog routine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.