Overview
- ReliaQuest says the campaign has been active since June 2026 and uses compromised public Wi‑Fi gateway devices at hotels and conference centers to redirect users to attacker‑controlled Microsoft‑lookalike sites for credential theft.
- Gateways under the attackers’ control can rewrite DNS answers for every connected device so browsers may show normal URLs while users are sent to malicious servers that mimic Microsoft 365 login pages.
- In roughly one‑third of observed cases attackers tried to abuse Windows’ WPAD proxy discovery to route broader application traffic through a malicious proxy and in a smaller number abused Microsoft’s device‑code sign‑in to obtain MFA‑cleared tokens.
- ReliaQuest assesses with low‑to‑medium confidence that initial access likely came through exposed internet‑facing management interfaces and weak or reused admin credentials on gateway appliances.
- Simple fixes can stop the attack: enforce always‑on full‑tunnel VPNs, use encrypted DNS in strict mode, disable WPAD where unused, block unnecessary device‑code flows, and have SOCs hunt for the identified domains and login anomalies; the tradecraft echoes past router campaigns but the researchers found no firm technical link to APT28.