INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365
| 2026-07-24 17:50 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
Hackers hijacked Wi-Fi DNS at hotels and conference centers, redirecting users to fake Microsoft 365 login pages since at least June. The attackers are believed to be similar to the Russian espionage group APT28 (a.k.a. Fancy Bear, Forest Blizzard), attributed to Russia. This campaign impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail, with affected entities likely being traveling employees worldwide, potentially numbering in the hundreds of thousands. The attack works by exploiting weakly protected management interfaces or vulnerabilities, allowing attackers to modify DNS settings to redirect legitimate connections to infrastructure under their control. As of now, the current status is that ReliaQuest has identified compromised Wi-Fi gateways globally and warned organizations about this ongoing threat.
Technical Mitigations AI-generated
• Use an always-on, full-tunnel VPN and encrypted DNS in strict mode to prevent attackers from forging plain-text requests.
• Disable WPAD (Web Proxy Auto-Discovery) to prevent attackers from responding with malicious proxy auto-configuration files.
• Review logs for suspicious activity related to the attack chain, including traffic to compromised Wi-Fi gateways and device-code authentication flows.
• Disable Device Code authentication flow in Microsoft Entra ID when not needed to prevent legitimate OAuth tokens from being issued to attackers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28
Target & Sectors
SA
IN
financefinance
healthhealth
hospitalityhospitality
retailretail
Incident Timeline
2026/07/24
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
Click on any entity below to view its context and source!
threat_actor
APT28
The researchers believe this activity is similar to the
FrostArmada router-based campaigns
attributed to the Russian espionage group APT28 (a.k.a. Fancy Bear, Forest Blizzard).
infrastructure
Microsoft 365
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts.
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
Since the devices serve corporate events, hijacking the Microsoft 365 accounts could give attackers access to sensitive business information, communications, and private documents.
infrastructure
Windows
…k steps
Source: ReliaQuest
In roughly one-third of the investigated cases, the attackers also attempted to abuse Web Proxy Auto-Discovery (WPAD) by responding to Windows' automatic WPAD lookup with a malicious proxy auto-configuration (PAC) file.
This theoretically would route traffic from Windows apps, including Chrome, through an attacker-controlled proxy, but ReliaQuest couldn’t confirm that these attacks were successful.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts.
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
Since the devices serve corporate events, hijacking the Microsoft 365 accounts could give attackers access to sensitive business information, communications, and private documents.
Metrics
infrastructure
Windows
Affected Product
…k steps
Source: ReliaQuest
In roughly one-third of the investigated cases, the attackers also attempted to abuse Web Proxy Auto-Discovery (WPAD) by responding to Windows' automatic WPAD lookup with a malicious proxy auto-configuration (PAC) file.
This theoretically would route traffic from Windows apps, including Chrome, through an attacker-controlled proxy, but ReliaQuest couldn’t confirm that these attacks were successful.
Intelligence Sources
BleepingComputer
2026-07-24
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:14
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Cybersecurity company ReliaQuest
entity
4x
industry
Targeted Sector
Legal
sector
2x
target region
Target Country
India
country
2x
tactic
Cyber Operation Type
Espionage
tactic
2x
infrastructure
Affected Product
Microsoft 365
software
2x
general metric
%
54
%
Contextual Telemetry
Context Block
4 METRICS
source region
Origin Country
Russian Federation
country
threat actor
APT Group
APT28
actor
general metric
Accounts
365
accounts
tactic
MITRE ATT&CK Technique
T1090 - Proxy
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.