Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
ID: b73692c3-062d-5336-8101-d22726da2097
STIX ID: report--b73692c3-062d-5336-8101-d22726da2097
Feed Name: GBHackers
ReliaQuest reports an active campaign compromising captive‑portal appliances at hotels and conference centers to perform gateway‑level DNS poisoning that redirects Microsoft 365 authentication traffic to attacker‑controlled hosts, enabling credential and OAuth token theft via AiTM proxies and device‑code abuse; observed IOCs include domains (m365-owa.com, owa-ms365.com, ms365-device.com, ms365-live.com), IPs (38.146.28.75, 31.57.243.154, 104.194.159.150) and a registrant email, and recommended mitigations are always‑on full‑tunnel VPN, strict DoH/DoT, WPAD hardening, and disabling device‑code flows where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
