Hotel Wi-Fi as New Attack Surface: DNS Poisoning Campaign Steals Microsoft 365 Logins Without a Single Click
- Campaign identified: Researchers uncovered adversaries compromising hospitality Wi-Fi captive portal gateways to hijack corporate accounts since at least June 2026.
- APT28 overlap: The tradecraft mirrors APT28 (Fancy Bear, Forest Blizzard) and the FrostArmada campaign.
- Primary defense: Always-on, full-tunnel VPN routes DNS through corporate resolvers and stops the attack at its source.
A widespread DNS poisoning campaign compromises hotel and conference center Wi-Fi captive portal gateways to steal Microsoft 365 credentials. A July 23, 2026, ReliaQuest Threat Research report said the threat actors do not rely on phishing emails, endpoint compromise, or malicious links – just logging onto hotel Wi-Fi is enough.
However, this also applies to any operator of a captive portal network, such as airports, conference centers, co-working spaces, universities, health care facilities, and event venues.
Gateway Compromise Enables Silent Credential Harvesting
Once attackers gain administrative access to a captive portal appliance, they control DNS resolution for every connected client. Forged DNS responses redirect Microsoft authentication traffic to attacker-controlled domains, including:
- m365-owa[.]com,
- owa-ms365[.]com,
- ms365-device[.]com,
- ms365-live[.]com.
ReliaQuest assesses with low-to-moderate confidence that initial access came through exposed management interfaces (internet-facing SSH, SNMP, and web admin consoles) where attackers leveraged weak or reused administrative credentials.
According to the report, the pattern of this campaign suggests it follows traveling employees wherever they connect, not the other way around.
WPAD Abuse and Device-Code Flow Exploitation
In some of the observed cases, attackers attempted Web Proxy Auto-Discovery (WPAD) abuse to route Windows application traffic through a malicious proxy. In a subset, they paired DNS poisoning with Microsoft device-code authentication flow abuse, pulling MFA-satisfied OAuth tokens without ever intercepting a password.
APT28 Tradecraft and FrostArmada Overlap
ReliaQuest assesses that the tradecraft resembles APT28, also tracked as Fancy Bear and Forest Blizzard – a Russian military intelligence group linked to the FrostArmada campaign disrupted in April 2026.
The overlap includes gateway-level DNS poisoning against Microsoft authentication domains and adversary-in-the-middle (AITM) account compromise. ReliaQuest's report states evidence suggests this actor could be a less sophisticated copycat.
Mitigation Advice
Compromised gateways have turned up across multiple U.S. cities and internationally in India and Saudi Arabia, with victim traffic spanning financial services, legal, healthcare, energy, and retail sectors. ReliaQuest suggests the following measures:
- Enforcing always-on, full-tunnel VPN configuration.
- Auditing proxy authentication logs for authentications from unknown hosts.
- Disabling Web Proxy Auto-Discovery (WPAD) where not required.
- Validating the site before entering credentials.
- Disabling the device code authentication flow at the identity provider.
This month, Kaspersky reported on device code phishing abusing Microsoft OAuth 2.0 to steal tokens, a topic for which Microsoft issued a critical security alert in March, saying it targets government and public organizations with the EvilProxy AITM framework.
In April, Cyber threat research collective Ctrl-Alt-Intel attributed a Russian hacking campaign targeting Ukraine and NATO to APT28. Around the same time, Microsoft revealed that the threat actor led a highly coordinated global espionage campaign compromising SOHO routers via sophisticated AITM attacks to steal sensitive credentials and monitor network communications.







