Public Wi-Fi Networks Used for Corporate Credential Phishing
Cybersecurity firm ReliaQuest has revealed that hackers, after compromising Wi-Fi gateways in hotels and conference centers, are targeting the Microsoft 365 accounts of traveling employees. Attackers are stealing credentials by redirecting traffic to their own fake sites.
What Happened
The cybersecurity world is facing a new and alarming attack campaign targeting traveling professionals. According to a report published by cybersecurity firm ReliaQuest, an unidentified threat actor is compromising Wi-Fi gateways in public venues like hotels and conference centers to steal the Microsoft 365 account credentials of corporate employees. The report states that the attacks have been ongoing since at least June 2026.
The primary targets of the attackers are employees, often on business trips, who connect to these public networks. The hackers use this compromised network infrastructure to unknowingly redirect users to fake websites under their control, thereby harvesting critically important corporate credentials. This method allows attackers to position themselves between the victim and the service they are connecting to, enabling them to monitor and manipulate all communication.
What Data Was Stolen
The primary target of this attack campaign is account information for the Microsoft 365 platform, which is widely used in the corporate world. With the stolen credentials, attackers aim to infiltrate corporate internal networks, email systems, and cloud storage. According to ReliaQuest's analysis, the data collected by the attackers includes:
- Microsoft 365 Usernames and Passwords: The main focus of the attack, this information is used for initial access to corporate networks.
- Other Sensitive Information: Through the Adversary-in-the-Middle (AitM) technique, attackers could also monitor other unencrypted or weakly encrypted traffic to access additional sensitive information. However, the source does not provide specific details on this.
These stolen credentials can serve as a stepping stone for larger cyberattacks, data breaches, or espionage activities.
How Did the Attack Happen
The attackers follow a multi-layered and technical method to achieve their goals. According to the ReliaQuest report, the attack chain consists of the following steps:
1. Compromise of Network Gateways: The first step of the attack is to breach the security of public Wi-Fi gateways (often SOHO - Small Office/Home Office type routers) used in hotels, conference centers, and other shared venues. Technical details on how these devices were compromised are not included in the report.
2. Modification of DNS Configuration: The hackers modify the DNS (Domain Name System) settings of the compromised routers. This action forms the basis of a technique known as "DNS Poisoning." Normally, when a user wants to go to Microsoft's login page, the DNS server directs them to the correct IP address. In this attack, however, the router directs all users to the IP address of a fake server controlled by the attacker.
3. Adversary-in-the-Middle (AitM) Attack: Thanks to the DNS redirection, the attackers place themselves between the victim and the internet. This is a classic Adversary-in-the-Middle (AitM) attack. While the victim thinks they are connecting to a legitimate site, all their traffic is actually passing through the attacker's infrastructure.
4. Fake Login Pages: The redirected users are met with fake websites (phishing lures) that perfectly imitate Microsoft's official login pages. ReliaQuest reported that it identified four different domains specifically registered by the attackers for this purpose.
5. Credential Theft: When victims enter their Microsoft 365 username and password on these fake pages, this information is sent directly to the attackers.
Who Was Affected
The attack poses a threat to all traveling corporate employees, rather than targeting a specific sector. ReliaQuest confirmed that traffic connecting to the compromised gateways came from a wide range of industries. The affected and potential targets include:
- Geographic Locations: The attacks were observed to be concentrated in venues in the US, India, and Saudi Arabia.
- Targeted Sectors: Employees from many different sectors, such as financial services, professional services, legal, healthcare, energy, and retail, were affected by these attacks.
- At-Risk Organizations: The report warns that any organization offering captive portal services (networks where users must pass through a web page to connect) faces a similar attack surface. These include airports, conference centers, healthcare facilities, universities, and event venues.
What Can You Do
Protecting against such attacks requires awareness and proactive measures for both individual users and organizations.
Recommendations for Individual Users:
- Use a VPN: Always use a trusted VPN (Virtual Private Network) service when connecting to public Wi-Fi networks. A VPN encrypts all your internet traffic, providing protection against Adversary-in-the-Middle attacks.
- Check the Address Bar: Before entering your credentials, make sure the website address (URL) is correct and uses HTTPS. Be wary of suspicious or misspelled domain names.
- Enable Multi-Factor Authentication (MFA): Activate MFA on your Microsoft 365 and all other important accounts. This prevents an attacker from accessing your account even if your password is stolen.
Recommendations for Organizations:
- Educate Employees: Regularly inform traveling employees about the risks of public Wi-Fi networks and phishing attacks.
- Enforce VPN Policies: Mandate the use of a VPN for external access to company resources.
- Monitor for Anomalous Logins: Use systems that monitor and generate alerts for login attempts to corporate accounts, especially those from unexpected geographic locations.
What the Company Says
ReliaQuest, which uncovered the attack, states that the campaign bears similarities to the previously observed FrostArmada campaign, which was attributed to APT28 (also known as Forest Blizzard, Fancy Bear), a group believed to be linked to Russia's GRU. However, the report also highlights significant differences.
According to ReliaQuest's analysis, "The Tactics, Techniques, and Procedures (TTPs) observed in the new campaign suggest that the threat actor has been at least reusing APT28’s tradecraft, but do not fully overlap with FrostArmada."
The key differences highlighted in the report are:
- Attack Method: The new attacker uses DNS poisoning to indiscriminately redirect all users to their infrastructure. According to ReliaQuest, this could be an "indicator of a less sophisticated or less careful actor than APT28."
- Targets: The targeting of captive portal appliances in hotels and conference centers is a method not previously documented in FrostArmada reporting.
- Infrastructure: The domain registrations and IP addresses used do not align with infrastructure previously seen in APT28 campaigns.
In conclusion, while it is not certain who is behind these attacks, it is clear they are using pages from a known state-sponsored group's playbook.
Source
https://www.securityweek.com/hacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.