Threat intelligence researchers published details on a new cyber espionage campaign codenamed CaptiveCrunch, operated by threat actor group Storm-2945. The operation targets public Wi-Fi networks in high-end hotels and convention centers commonly frequented by corporate executives and technology builders.

When users connect to the travel network, the attacker executes a Man-in-the-Middle (MitM) attack to hijack HTTP web traffic, displaying a mandatory "Browser Update Required" prompt. Users who download the update execute a new remote access trojan (RAT) known as CornFlake, granting attackers stealthy persistence to capture webcam feeds, record audio, log keystrokes, and extract local system credentials.

The Pipeline to Crypto Theft

Web3 founders, core developers, and OTC traders travel constantly for industry hackathons and summits. Capturing a developer laptop via travel Wi-Fi yields direct pathways to protocol drains:

CornFlake RAT actively targets local browser profile directories. It extracts session cookies, stored password vaults, and local storage data for browser wallet extensions (such as MetaMask, Rabby, or Phantom). If an unencrypted seed phrase or active vault state is cached in local memory, the attacker immediately exfiltrates it to drain personal and treasury wallets.

Developers traveling with active SSH keys, .env file backups, or cloud provider API tokens (AWS, GCP, Vercel) unwittingly hand over administrative control of live dApp deployments. Attackers leverage captured credentials to push stealth drainer scripts directly to production frontends or manipulate smart contract deployment scripts.