Particle.news
Download on the App Store

Attackers Hijack Hotel and Conference Wi‑Fi to Steal Microsoft 365 Access

By changing DNS on captive‑portal gateway appliances attackers can silently route traveling employees to fake Microsoft sign‑in flows that may capture passwords or yield valid MFA session tokens unless networks enforce strict protections.

Overview

  • ReliaQuest says the campaign has been active since June 2026 and uses compromised public Wi‑Fi gateway devices at hotels and conference centers to redirect users to attacker‑controlled Microsoft‑lookalike sites for credential theft.
  • Gateways under the attackers’ control can rewrite DNS answers for every connected device so browsers may show normal URLs while users are sent to malicious servers that mimic Microsoft 365 login pages.
  • In roughly one‑third of observed cases attackers tried to abuse WindowsWPAD proxy discovery to route broader application traffic through a malicious proxy and in a smaller number abused Microsoft’s device‑code sign‑in to obtain MFA‑cleared tokens.
  • ReliaQuest assesses with low‑to‑medium confidence that initial access likely came through exposed internet‑facing management interfaces and weak or reused admin credentials on gateway appliances.
  • Simple fixes can stop the attack: enforce always‑on full‑tunnel VPNs, use encrypted DNS in strict mode, disable WPAD where unused, block unnecessary device‑code flows, and have SOCs hunt for the identified domains and login anomalies; the tradecraft echoes past router campaigns but the researchers found no firm technical link to APT28.