Hackers poison hotel Wi‑Fi to harvest Microsoft 365 logins

Hackers compromised captive‑portal Wi‑Fi gateways at hotels, conference centers and other venues, poisoning DNS to redirect users and harvest Microsoft 365 credentials.

ReliaQuest reported that a threat actor has been compromising captive‑portal Wi‑Fi gateway appliances at hotels, conference centers and other shared venues. The activity has been ongoing since at least June 2026 and affected networks in the United States, India and Saudi Arabia.

Attackers altered DNS configurations on small office/home office routers and gateway appliances so that users who connected to venue Wi‑Fi were routed to infrastructure controlled by the threat actor. On that infrastructure, web pages impersonating Microsoft login screens collected Microsoft 365 usernames and passwords. The use of captive portals-the login or acceptance pages shown to Wi‑Fi users-allowed adversary‑in‑the‑middle interception of traffic.

ReliaQuest identified four domains registered by the attackers and observed traffic to compromised gateways from employees at organizations in financial services, professional services, legal, health care, energy and retail. Because DNS settings on the gateways redirected all users to attacker servers, the operation enabled broad credential harvesting rather than selective device targeting.

The firm found similarities between the new activity and an earlier campaign known as FrostArmada, linked in past reporting to APT28. ReliaQuest reported differences in infrastructure and targeting: the domain registrations and IP addresses observed do not match those previously tied to APT28, and the targeting of captive‑portal appliances in hotels and conference centers had not been documented in earlier reports. ReliaQuest said the use of DNS poisoning to redirect every user differs from the more selective approaches seen before.

ReliaQuest advised that any organization operating captive Wi‑Fi services-airports, conference centers, health facilities, universities and event venues-faces a comparable exposure. The firm published indicators of compromise tied to the domains and gateway behavior it observed and recommended that operators check gateway DNS settings and monitor for unexpected redirects.

Articles by this author