Hackers target hotel and conference Wi-Fi to steal Microsoft 365 accounts

 

Hackers target hotel and conference Wi-Fi to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. The campaign has been active since at least June and has affected organizations in industries including finance, healthcare, legal, energy, retail, and professional services.

Cybersecurity company ReliaQuest found compromised Wi-Fi gateways in several US cities, as well as in India and Saudi Arabia. Researchers believe the attackers are mainly targeting business travelers who connect to the networks during corporate events.

The activity is similar to the router-based FrostArmada attacks linked to the Russian hacking group APT28, also known as Fancy Bear. Researchers believe the hackers may have gained access by exploiting weak passwords, exposed management systems, or security flaws in the Wi-Fi devices.

After taking control of a gateway, attackers change its DNS settings to send users to fake Microsoft login websites. In some cases, the attackers used Microsoft's Device Code authentication process. Instead of stealing passwords, victims unknowingly approved a login request that gave the hackers a valid OAuth token, allowing them to bypass multi-factor authentication (MFA).

Researchers also observed attempts to abuse Windows' Web Proxy Auto-Discovery (WPAD) feature, which could route internet traffic through attacker-controlled servers, although it’s not clear if the attacks were successful.

ReliaQuest warns that using public DNS services like Google’s 8.8.8.8 does not stop the attack because the compromised gateway intercepts requests before they reach the DNS server.

To reduce the risk, the company recommends using an always-on VPN with encrypted DNS, disabling WPAD where possible, monitoring network logs for suspicious activity, and turning off Device Code authentication in Microsoft Entra ID if it is not needed.


Back to the list