Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
ID: a1672051-231d-50e5-abab-b4a4b9f759fd
STIX ID: report--a1672051-231d-50e5-abab-b4a4b9f759fd
Feed Name: Infosecurity Magazine (News)
ReliaQuest warns of a global DNS poisoning campaign targeting public Wi‑Fi routers at hotels, conference centers and other venues frequented by corporate travelers; attackers exploit exposed management interfaces and weak/reused admin credentials to modify router DNS and transparently harvest usernames, passwords and other sensitive data. The activity, observed across multiple US cities, India and Saudi Arabia, is ongoing and described as similar to TTPs attributed to APT28; mitigations recommended include enforcing always‑on full‑tunnel VPNs, auditing proxy authentication logs, disabling WPAD, validating sites before entering credentials, and blocking device‑code authentication flows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
