DNS Poisoning Tactics Expand to Hospitality Wi-Fi
ID: 1f7aa53e-4fb4-5dc9-b85d-ba880e894360
STIX ID: report--1f7aa53e-4fb4-5dc9-b85d-ba880e894360
Feed Name: ReliaQuest Blog
ReliaQuest describes an ongoing campaign (since at least June 2026) where threat actors compromise hotel and other captive-portal Wi‑Fi gateways to perform DNS poisoning that redirects Microsoft 365 authentication to attacker-controlled hosts; observed techniques include WPAD abuse and device-code flow authorization to obtain MFA-satisfied OAuth tokens. The report provides observed malicious domains and IPs, links the tradecraft to prior FrostArmada/APT28 activity by TTP overlap, and recommends defenses—most importantly enforcing always-on full-tunnel VPN, disabling WPAD, auditing proxy logs, and blocking device-code authentication flow in Entra ID.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
