Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Incidents: Russian APT Storm-2945 hijacks public Wi-Fi gateways to steal credentials via DNS manipulation and AitM attacks.
Deep Analysis and Expert Commentary
The attack path begins with compromising SOHO routers and captive portal networks, likely through shared service vulnerabilities. Storm-2945 then modifies DNS configurations to redirect traffic to attacker-controlled servers, enabling credential interception via AitM. The campaign leverages Golang-based RATs (CornFlake) and PowerShell infostealers (ChocoShell) for reconnaissance and data exfiltration. Targeting Windows and Android users, the group employs ClickFix techniques to deliver malware disguised as browser updates. Mitigations include enforcing multi-factor authentication (MFA), monitoring DNS configurations for unauthorized changes, and educating employees on phishing risks in public Wi-Fi environments. Organizations should also segment captive portal networks from critical infrastructure.
Action Items
- Implement MFA for all Microsoft 365 and critical system access.
- Monitor and audit DNS configurations for unauthorized changes.
- Train employees on recognizing phishing attempts, especially when using public Wi-Fi.
Original Article Brief Intro
SecurityWeek · 2026-08-03 · Incidents: Russian APT Storm-2945 hijacks public Wi-Fi gateways to steal credentials via DNS manipulation and AitM attacks.
Related Terms and Notes
Threat Actors
- APT29
Malware Families
- RAT — Remote Access Trojan, malware that provides attackers with control over infected systems.
Techniques / TTPs
- AitM — Adversary-in-the-middle technique where attackers intercept and manipulate communication between two parties.
- Credential Theft
- Phishing
Context Notes
- AitM
- APT
- CaptiveCrunch
- DNS Manipulation
- Midnight Blizzard
- Storm-2945
- Wi-Fi Hacking