Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
ID: 73c62d01-f984-5237-a38e-f453e0550ebf
STIX ID: report--73c62d01-f984-5237-a38e-f453e0550ebf
Feed Name: Security Affairs
Researchers observed an active campaign since at least June 2026 in which attackers compromise hotel and conference Wi‑Fi gateways to perform DNS-based redirection to fake Microsoft 365 login domains (e.g., m365-owa.com, ms365-live.com), steal credentials, abuse WPAD to route broader traffic through attacker proxies, and sometimes bypass MFA via device-code approval; the activity shares tradecraft with FrostArmada/APT28 and is mitigated by full-tunnel corporate VPNs, strict DNS-over-HTTPS/TLS, and disabling WPAD.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
