Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How to Negotiate Your Salary Before You Say Yes

    July 29, 2026

    Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books

    July 29, 2026

    The Download: a chip talent battle, and deflating AI hype

    July 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How to Negotiate Your Salary Before You Say Yes
    • Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books
    • The Download: a chip talent battle, and deflating AI hype
    • Global AI Digital Divide Shapes Who Builds AI
    • More Typos, Fewer Em Dashes: Writers Are Creating an Anti-AI ‘Literary Counterculture’
    • The AI Hype Index: Unsexy AI
    • OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
    • Why Scientists Redesigned the Botox Enzyme With AI
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
    Cybersecurity

    Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 25, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Credit card theft campaign abuses Stripe to host stolen payment info
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.

    The campaign has been ongoing since at least June and impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail.

    Cybersecurity company ReliaQuest identified compromised Wi-Fi gateways in multiple U.S. cities as well as other regions of the world, such as India and Saudi Arabia.

    Since the devices serve corporate events, hijacking the Microsoft 365 accounts could give attackers access to sensitive business information,  communications, and private documents.

    “We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail- confirming this isn’t sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect,” ReliaQuest says.

    The researchers believe this activity is similar to the FrostArmada router-based campaigns attributed to the Russian espionage group APT28 (a.k.a. Fancy Bear, Forest Blizzard).

    Attack chain

    It is unclear how initial access to the Wi-Fi appliances was gained, but ReliaQuest says the threat actor could have exploited weakly protected, exposed management interfaces (e.g., SSH, SNMP, web admin dashboards) or vulnerabilities.

    Once the attacker gains administrator access, they can modify the gateway’s DNS settings to redirect connections to legitimate domains to infrastructure under the attacker’s control.

    ReliaQuest says that the attacker registered at least four domains for setting up fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.

    With DNS settings changed, users trying to access legitimate Microsoft login portals would land on the hacker’s phishing pages and enter their credentials.

    In some cases, the researchers observed a device-code authentication flow in which targets were redirected to a fake Microsoft page with a prompt.

    “What the user can’t see is that approving the prompt authorizes a session initiated by the attacker,” ReliaQuest says. The researchers note that authorizing the attacker-initiated request causes a legitimate OAuth token to be issued to the attacker’s client.

    This bypasses the multi-factor authentication (MFA) protection without stealing any credentials or intercepting access tokens.

    The attack steps
    Source: ReliaQuest

    In roughly one-third of the investigated cases, the attackers also attempted to abuse Web Proxy Auto-Discovery (WPAD) by responding to Windows’ automatic WPAD lookup with a malicious proxy auto-configuration (PAC) file.

    This theoretically would route traffic from Windows apps, including Chrome, through an attacker-controlled proxy, but ReliaQuest couldn’t confirm that these attacks were successful.

    The researchers also emphasized that using public DNS servers such as Google’s 8.8.8.8 does not prevent this attack, as the gateway forges the plain-text requests before they reach the intended resolver.

    ReliaQuest recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode as solid protection measures against these attacks.

    Additionally, the cybersecurity company recommends disabling WPAD, reviewing logs for suspicious activity, and disabling Device Code authentication flow in Microsoft Entra ID when not needed.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    accounts DNS hackers hijack hotel Microsoft steal WiFi
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • How to Negotiate Your Salary Before You Say Yes
    • Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books
    • The Download: a chip talent battle, and deflating AI hype
    • Global AI Digital Divide Shapes Who Builds AI
    • More Typos, Fewer Em Dashes: Writers Are Creating an Anti-AI ‘Literary Counterculture’

    How to Negotiate Your Salary Before You Say Yes

    July 29, 2026

    Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books

    July 29, 2026

    The Download: a chip talent battle, and deflating AI hype

    July 29, 2026

    Global AI Digital Divide Shapes Who Builds AI

    July 29, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.