July 26, 2026

Hotel Wi-Fi DNS Hijacking Campaign Steals Microsoft 365 Credentials via Fake Login Portals

Hotel Wi-Fi DNS Hijacking Campaign Steals Microsoft 365 Credentials via Fake Login Portals

Security researchers at ReliaQuest have uncovered an active campaign, running since at least June 2026, in which threat actors hijack the DNS settings of Wi-Fi gateways at hotels and conference centers to redirect guests toward fake Microsoft 365 login pages. Compromised Wi-Fi gateways have been identified in multiple U.S. cities as well as other regions, including India and Saudi Arabia. Because these gateways serve corporate travelers and event attendees, hijacking Microsoft 365 accounts could give attackers access to sensitive business information, communications, and private documents across a wide range of industries.

The initial access vector into the Wi-Fi appliances themselves remains unconfirmed, but ReliaQuest suggests the threat actor may have exploited weakly protected, exposed management interfaces such as SSH, SNMP, or web admin dashboards, or leveraged unpatched vulnerabilities. Once administrative access is obtained, the attacker modifies the gateway's DNS settings so that connections to legitimate domains are redirected to attacker-controlled infrastructure. Researchers identified at least four lookalike domains registered for the fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.

A particularly notable technique observed in this campaign involves abuse of Microsoft's device-code authentication flow. In some cases, victims were redirected to a fake Microsoft page containing a prompt, and while the user cannot see it, approving that prompt authorizes a session that the attacker initiated. Approving the attacker's request causes a legitimate OAuth token to be issued directly to the attacker's client, meaning the multi-factor authentication protection is bypassed without any credentials being stolen or access tokens intercepted.

Beyond credential and token theft, roughly one-third of the investigated cases showed attackers also attempting to abuse Windows' Web Proxy Auto-Discovery (WPAD) protocol by serving a malicious proxy auto-configuration file, which could theoretically route traffic from Windows applications through an attacker-controlled proxy — though ReliaQuest could not confirm these specific attempts succeeded. Notably, switching to public DNS resolvers such as Google's 8.8.8.8 does not protect against this attack, since the compromised gateway intercepts and forges plain-text DNS requests before they ever reach the intended resolver. Researchers also noted similarities to earlier FrostArmada router-based campaigns attributed to the Russian espionage group APT28 (also known as Fancy Bear or Forest Blizzard).

To defend against this threat, ReliaQuest recommends using an always-on, full-tunnel VPN combined with encrypted DNS in strict mode, since these measures prevent a compromised local network from tampering with DNS resolution. Additional recommended mitigations include disabling WPAD, reviewing network logs for suspicious activity, and disabling the Device Code authentication flow in Microsoft Entra ID when it isn't needed for legitimate business purposes. Organizations with employees who frequently travel or attend conferences should treat any hotel or venue Wi-Fi as inherently untrusted and enforce these controls at the endpoint level rather than relying on network-level trust.

Hotel Wi-Fi DNS Hijacking Campaign Steals Microsoft 365 Credentials via Fake Login Portals


Reference links:

  1. Authorities disrupt DNS hijacks used to steal Microsoft 365 logins (FrostArmada/APT28 background) – BleepingComputer
  2. New phishing kits target Microsoft 365 accounts, evade MFA – BleepingComputer
  3. Original BleepingComputer report: Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Popular post in the past 30 days