logo

Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials

ID: 73c62d01-f984-5237-a38e-f453e0550ebf

STIX ID: report--73c62d01-f984-5237-a38e-f453e0550ebf

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-07-26

Date Updated: 2026-07-27

Author: Pierluigi Paganini

...
...

Researchers observed an active campaign since at least June 2026 in which attackers compromise hotel and conference Wi‑Fi gateways to perform DNS-based redirection to fake Microsoft 365 login domains (e.g., m365-owa.com, ms365-live.com), steal credentials, abuse WPAD to route broader traffic through attacker proxies, and sometimes bypass MFA via device-code approval; the activity shares tradecraft with FrostArmada/APT28 and is mitigated by full-tunnel corporate VPNs, strict DNS-over-HTTPS/TLS, and disabling WPAD.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.