logo

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

ID: 1f7aa53e-4fb4-5dc9-b85d-ba880e894360

STIX ID: report--1f7aa53e-4fb4-5dc9-b85d-ba880e894360

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

...
...

ReliaQuest describes an ongoing campaign (since at least June 2026) where threat actors compromise hotel and other captive-portal Wi‑Fi gateways to perform DNS poisoning that redirects Microsoft 365 authentication to attacker-controlled hosts; observed techniques include WPAD abuse and device-code flow authorization to obtain MFA-satisfied OAuth tokens. The report provides observed malicious domains and IPs, links the tradecraft to prior FrostArmada/APT28 activity by TTP overlap, and recommends defenses—most importantly enforcing always-on full-tunnel VPN, disabling WPAD, auditing proxy logs, and blocking device-code authentication flow in Entra ID.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.