logo

Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing

ID: b73692c3-062d-5336-8101-d22726da2097

STIX ID: report--b73692c3-062d-5336-8101-d22726da2097

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Mayura Kathir

...
...

ReliaQuest reports an active campaign compromising captive‑portal appliances at hotels and conference centers to perform gateway‑level DNS poisoning that redirects Microsoft 365 authentication traffic to attacker‑controlled hosts, enabling credential and OAuth token theft via AiTM proxies and device‑code abuse; observed IOCs include domains (m365-owa.com, owa-ms365.com, ms365-device.com, ms365-live.com), IPs (38.146.28.75, 31.57.243.154, 104.194.159.150) and a registrant email, and recommended mitigations are always‑on full‑tunnel VPN, strict DoH/DoT, WPAD hardening, and disabling device‑code flows where possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.