« cette manœuvre installe des trojans comme CornFlake »
CornFlake
CornFlake is a Go-based remote access trojan (RAT) targeting Windows systems.
Profile source: Mallory opens in a new tabCornFlake
Family profile
CornFlake is a Go-based remote access trojan (RAT) targeting Windows systems. It is assessed as Storm-2945’s primary persistent implant in the CaptiveCrunch espionage campaign, which has been linked to the Russia-aligned Midnight Blizzard (APT29) threat actor. The campaign targeted corporate travelers through compromised captive-portal infrastructure at hospitality and conference venues, using ClickFix-style fake browser or operating-system update lures to persuade victims to execute the malware. CornFlake presents a deceptive progress interface during installation and establishes redundant persistence through Windows services, Run-key entries, scheduled tasks, and a watchdog mechanism that can restore removed persistence. It communicates with command-and-control infrastructure through an encrypted channel and supports remote shell access, host reconnaissance, keylogging, clipboard monitoring, screenshot capture, microphone and webcam surveillance, browser credential and cookie theft, Microsoft 365 session-token theft, removable-media monitoring, and file exfiltration.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Persistence
- Post Exploitation
- Reconnaissance
- Session Hijacking
Reported operators
Threat actors
4 named in public reportingMicrosoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware.
One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.
One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.
MITRE ATT&CK