Skip to content

CornFlake

CornFlake is a Go-based Windows remote access trojan used as the primary persistent implant in the CaptiveCrunch espionage campaign attributed by Microsoft to Storm-2945, a sub-cluster of Midnight Blizzard (APT29), which Western governments have linked to Russia’s SVR.

Profile source: Mallory opens in a new tab

CornFlake

Family profile

CornFlake is a Go-based Windows remote access trojan used as the primary persistent implant in the CaptiveCrunch espionage campaign attributed by Microsoft to Storm-2945, a sub-cluster of Midnight Blizzard (APT29), which Western governments have linked to Russia’s SVR. It is designed to provide long-term access to compromised Windows systems and to support credential theft, surveillance, reconnaissance, and data exfiltration against targets that appear to include corporate travelers and organizations of intelligence interest.

CornFlake has been delivered through captive-portal traffic manipulation on hospitality and conference Wi-Fi networks, where victims are redirected to fake browser or operating system update pages using ClickFix-style social engineering. During installation it displays a fake progress or update window to reduce suspicion, then establishes durable persistence through multiple mechanisms including Windows service registration, Run-key persistence, scheduled tasks, and a watchdog routine that restores removed persistence components. It masquerades as a legitimate cloud synchronization service to blend into the host environment.

The malware supports a broad post-compromise feature set. Reported capabilities include remote shell access, keylogging, clipboard monitoring, screenshot capture, microphone and webcam surveillance, browser credential theft, cookie theft, Microsoft 365 session token theft, file exfiltration, USB monitoring, and host reconnaissance. It also collects system intelligence and supports encrypted command-and-control communications using modern cryptographic key exchange. Some reporting indicates it exposes a local HTTP API that can support modular tasking and companion payloads such as ChocoShell.

Operationally, CornFlake functions as the persistence and remote-control component of a broader intrusion set that also includes ChocoShell, an in-memory PowerShell stealer, and FruitStone, a web-based management panel. The malware is associated with espionage-oriented collection rather than disruptive effects, with emphasis on maintaining access, harvesting credentials and sessions, monitoring victim activity, and extracting files and other sensitive data from Windows endpoints.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • ES1

Leading providers

  • Ultahost, Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
APT29

Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware.

Storm-2945

Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware.

SVR

One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.

Nobellium

One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks.

MITRE ATT&CK

CornFlake in ATT&CK

44 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.