Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
Threat actors are compromising public Wi-Fi gateway appliances in hotels and conference centers to steal Microsoft 365 credentials from traveling employees. Attackers modify DNS configurations on SOHO routers to redirect users to attacker-controlled infrastructure for credential harvesting via adversary-in-the-middle (AitM) techniques. The campaign, ongoing since at least June 2026, shares TTPs with the FrostArmada group (APT28/Forest Blizzard/Fancy Bear) but uses less sophisticated methods like
Analysis
TL;DR
- Threat actors are compromising public Wi-Fi gateway appliances in hotels and conference centers to steal Microsoft 365 credentials from traveling employees.
- Attackers modify DNS configurations on SOHO routers to redirect users to attacker-controlled infrastructure for credential harvesting via adversary-in-the-middle (AitM) techniques.
- The campaign, ongoing since at least June 2026, shares TTPs with the FrostArmada group (APT28/Forest Blizzard/Fancy Bear) but uses less sophisticated methods like broad DNS poisoning instead of targeted redirection.
- Four attacker-registered domains were used to impersonate Microsoft login pages, targeting users across multiple industries including finance, healthcare, energy, and retail.
- Organizations operating captive portal networks—including airports, universities, and event venues—are at risk due to exposed gateway devices.
Why It Matters
This attack vector highlights a critical gap in enterprise security: the vulnerability of third-party or shared network infrastructure that organizations rely on during travel. As remote work and hybrid models become standard, securing endpoints beyond corporate perimeters is essential—especially when attackers exploit trust in public Wi-Fi services to bypass traditional defenses.
Technical Details
- Attackers gain access to small office/home office (SOHO) routers deployed in captive portal environments by exploiting weak authentication or unpatched firmware.
- Once inside, they alter DNS settings to force all connected clients through malicious servers designed to mimic legitimate Microsoft 365 login portals.
- The use of DNS poisoning affects every user connecting to the compromised network, increasing scale and detection difficulty compared to spear-phishing approaches.
- Credential theft occurs via real-time interception using AitM proxies that forward traffic after capturing usernames, passwords, and potentially session tokens.
- Infrastructure includes four newly registered domains specifically crafted to resemble official Microsoft sign-in pages, often hosted on cloud platforms to evade early takedowns.
Industry Insight
Organizations must treat public Wi-Fi as an untrusted zone and enforce strict endpoint compliance checks before allowing access to sensitive systems—even for authorized travelers. Security teams should consider deploying DNS filtering solutions at the organizational level to block known malicious domains and monitor for anomalous DNS queries originating from guest networks. Additionally, implementing multi-factor authentication (MFA) with phishing-resistant methods such as FIDO2 keys can significantly reduce the impact of stolen credentials even if users fall victim to these lures.
Disclaimer: The above content is generated by AI and is for reference only.