The record
Written from the 1 report below. Nothing here is unsourced.
- Hackers have been changing the DNS settings on Wi-Fi gateways at hotels and conference centers since at least June to redirect users to fake Microsoft 365 login pages, according to cybersecurity firm ReliaQuest.
- Compromised gateways were found in multiple U.S. cities and in regions including India and Saudi Arabia, with traffic observed from organizations in financial services, professional services, legal, health care, energy and retail, indicating the campaign targets traveling employees across sectors.
- Because the devices serve corporate events, hijacked Microsoft 365 accounts could expose sensitive business information, communications and private documents, and in some cases the attackers used a device-code approval trick that bypasses multi-factor authentication without stealing credentials.
- ReliaQuest believes the activity resembles router-based campaigns linked to the Russian espionage group APT28 and recommends an always-on full-tunnel VPN, encrypted DNS, disabling WPAD and disabling the Device Code authentication flow in Microsoft Entra ID when not needed.
What to watch next
- How attackers initially gained access to the Wi-Fi appliances, whether through exposed management interfaces or unpatched vulnerabilities, remains unknown.
- ReliaQuest could not confirm whether the WPAD proxy-hijacking attempts actually succeeded, so further findings on that are worth watching.
- Whether more compromised gateways are discovered in additional locations, including India, and whether the campaign is formally tied to APT28.
Coverage1
1 report
International1
All filed from United States
Named United States · India · Saudi Arabia · Chrome · Microsoft · Microsoft 365 · Microsoft Entra ID · Wi-Fi gateways · Windows · APT28 · FrostArmada · Google
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
