Skip to content
Tech News
← Back to articles

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

read original more articles
Why This Matters

This campaign highlights the growing threat of cybercriminals hijacking hotel Wi-Fi networks to steal Microsoft 365 credentials, potentially exposing sensitive business data across multiple industries. It underscores the importance of securing Wi-Fi infrastructure and being vigilant when connecting to public networks. As cyber threats evolve, both organizations and consumers must prioritize cybersecurity measures to prevent data breaches.

Key Takeaways

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.

The campaign has been ongoing since at least June and impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail.

Cybersecurity company ReliaQuest identified compromised Wi-Fi gateways in multiple U.S. cities as well as other regions of the world, such as India and Saudi Arabia.

Since the devices serve corporate events, hijacking the Microsoft 365 accounts could give attackers access to sensitive business information, communications, and private documents.

“We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail- confirming this isn't sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect,” ReliaQuest says.

The researchers believe this activity is similar to the FrostArmada router-based campaigns attributed to the Russian espionage group APT28 (a.k.a. Fancy Bear, Forest Blizzard).

Attack chain

It is unclear how initial access to the Wi-Fi appliances was gained, but ReliaQuest says the threat actor could have exploited weakly protected, exposed management interfaces (e.g., SSH, SNMP, web admin dashboards) or vulnerabilities.

Once the attacker gains administrator access, they can modify the gateway’s DNS settings to redirect connections to legitimate domains to infrastructure under the attacker's control.

ReliaQuest says that the attacker registered at least four domains for setting up fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.

... continue reading