Overview
- ReliaQuest disclosed Monday that the campaign has run since at least June 2026 and that attackers have changed DNS on captive‑portal gateway appliances at hotels and conferences in the US, India and Saudi Arabia.
- Compromised gateways returned false DNS answers that redirected users to attacker‑run domains such as m365-owa.com to harvest Microsoft 365 credentials without phishing emails or malware.
- In about one third of observed cases attackers attempted to abuse Windows’ WPAD proxy discovery to route wider application traffic through a malicious proxy and in a smaller number of cases they abused Microsoft’s device‑code flow to gain MFA‑cleared sessions.
- ReliaQuest assesses initial access likely came from exposed management interfaces such as internet‑facing SSH or web consoles combined with weak or reused admin passwords, though that finding carries low‑to‑medium confidence.
- Defenses are practical and immediate: enforce always‑on full‑tunnel VPNs, use encrypted DNS in strict mode, disable WPAD, restrict or block device‑code sign‑ins at the identity provider, and train travelers to verify site certificates before entering credentials.