One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers
ID: 8c8796d5-b6aa-5a56-93d0-3f63aad77c49
STIX ID: report--8c8796d5-b6aa-5a56-93d0-3f63aad77c49
Feed Name: cybersecurityNews.com
Reliaquest reported a widespread campaign in which attackers compromise hotel and conference captive-portal gateways (via exposed management interfaces or weak credentials) to poison DNS responses and redirect guests to attacker-controlled Microsoft 365 lookalike sites, harvesting credentials and abusing the device-code/OAuth flow to gain access despite MFA. The activity has been observed across multiple countries and sectors, includes specific IoCs (domains, IPs, registrant email), and the report provides defensive guidance: enforce always-on full-tunnel VPN, use strict DNS over HTTPS/TLS, disable WPAD, and block device-code authentication paths via Conditional Access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
