
Fake Advisors, ClickFix, and Chrome Sync Spying
This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…
Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in pages. Victims are then tricked into completing a device-code login that grants attackers a legitimate session token, often bypassing MFA. This is a realistic scenario to simulate for traveling staff because it relies on a believable “Microsoft 365 login” workflow on public Wi‑Fi.
This campaign begins at the network level rather than in an inbox. Attackers gain administrative access to Wi-Fi gateways at hotels and conference centers and modify DNS configurations so that connected devices are pointed toward look-alike domains instead of legitimate Microsoft services. Because the redirection happens at the gateway, the malicious sign-in page can appear immediately after a traveler joins the network, often before they have any reason to be suspicious.
Once on the fake page, victims are guided through a device-code authentication flow. Instead of typing a password into an obvious clone, they are prompted to enter a code shown on screen to "continue signing in." Completing this step actually authorizes an attacker-initiated session, and the attacker receives a legitimate OAuth token, one that bypasses multi-factor authentication entirely because the victim technically completed a valid, if manipulated, authentication step.
The actors have also attempted to abuse Web Proxy Auto-Discovery (WPAD) with malicious proxy auto-configuration files, giving them another path to route victim traffic through infrastructure they control.
Several conditions make this scenario effective:
Organizations should enforce always-on, full-tunnel VPNs for traveling staff, use encrypted DNS in strict mode, disable WPAD where it is not needed, and disable the device-code authentication flow in Microsoft Entra ID where it is not required for business use. Employees should be trained to treat unexpected sign-in pages and device-code prompts on public Wi-Fi as suspicious, verify the web address before entering credentials, and report unapproved authorization requests rather than completing them.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromise hotel and conference Wi-Fi gateways and change DNS settings so travelers are silently redirected to fraudulent Microsoft 365 login pages instead of the real service.
Yes. Victims are tricked into completing a device-code authentication flow that authorizes an attacker-initiated session, producing a legitimate OAuth token that bypasses MFA.
Watch for sign-in prompts appearing unexpectedly right after joining public Wi-Fi, unfamiliar login domains, and device-code prompts you did not initiate yourself.
Enforce always-on, full-tunnel VPNs, use encrypted DNS in strict mode, disable WPAD, and disable the device-code authentication flow in Microsoft Entra ID.
You connect to hotel Wi‑Fi, open your browser, and boom, “Microsoft 365 Sign‑in” pops up before you do anything. In this scam, hotel and conference Wi‑Fi gateways are hacked so DNS sends you to fake Microsoft 365 pages like m365-owa.com or ms365-live.com, then a device-code screen asks you to 'enter the code to continue signing in.' Here’s the twist: that device-code flow authorizes their session, not yours, giving them a real OAuth token that can slip past MFA, all because you trusted a sign-in page that appeared right after joining public Wi‑Fi on an unfamiliar URL. Travel rule: on hotel or conference Wi‑Fi, if a Microsoft 365 login or device-code prompt appears unexpectedly, stop, check that the address is a real Microsoft domain, and if it’s not, close it and connect through your corporate VPN.

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…