
Hotel Wi‑Fi Redirect Scam Steals Microsoft 365 Logins
Attackers are compromising hotel and conference center Wi‑Fi gateways and changing DNS settings so business travelers are silently redirected to fake Microsoft…
ReliaQuest reports attackers are compromising public Wi‑Fi “captive portal” gateways (such as in hotels and conference centers) and changing their DNS settings to redirect users to attacker-controlled pages. The goal is to harvest traveling employees’ Microsoft 365 credentials using Microsoft-impersonation lures and adversary-in-the-middle interception.
According to ReliaQuest, a threat actor compromised public Wi-Fi gateway appliances used to run captive portal networks at hotels, conference centers, and other shared venues. Rather than building phishing pages from scratch, the attackers modified the DNS configurations of these compromised gateways so that anyone who connected would be redirected to attacker-controlled infrastructure. When a traveling employee joined the venue Wi-Fi, they were presented with a page impersonating the Microsoft 365 sign-in screen and prompted to authenticate to get internet access. Entering an email and password, and in some cases MFA or session details, handed credentials directly to the attackers.
This approach works because it targets a moment when employees have low guard: joining Wi-Fi at a venue they are only visiting temporarily. A login prompt during that process can feel routine rather than suspicious, especially when it visually resembles a familiar Microsoft sign-in page. Because the DNS change happens at the gateway level, every user who connects through that compromised appliance can be redirected, not just a single targeted individual. This gives attackers broad reach across many organizations and industries without needing to send a single phishing email.
ReliaQuest identified attacker-registered domains used to deliver these Microsoft-impersonation lures, and noted the infrastructure and tactics differ from the FrostArmada/APT28 campaign, which may point to a less sophisticated or less careful actor behind this activity.
Because victims spanned hospitality, healthcare, universities, financial services, and other sectors, this looks like opportunistic targeting of traveling employees generally, rather than an attack aimed at one industry.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
According to ReliaQuest, attackers hacked public Wi-Fi gateway appliances that run captive portal networks and changed their DNS configurations to redirect connected users to attacker-controlled infrastructure.
The captive portal redirected users to a page impersonating Microsoft 365 sign-in, asking them to enter their email and password, and potentially MFA or session details, to gain internet access.
Traveling employees who connect to shared venue Wi-Fi at hotels, conference centers, or similar locations are the primary targets, spanning many industries rather than one specific sector.
ReliaQuest notes this campaign uses different infrastructure than FrostArmada/APT28 and relies on DNS poisoning to redirect all connected users, which may indicate a less sophisticated or less careful actor.
You sit down at a hotel, join the Wi‑Fi, and a page pops up: “Sign in with Microsoft to access Wi‑Fi.” Looks normal, right? ReliaQuest found someone hacking hotel and conference Wi‑Fi gateways, quietly changing DNS so that captive portals redirect to fake Microsoft 365 pages that steal your work login. Here’s the trick: the portal looks like Microsoft, but the browser address bar is some random domain, not login.microsoftonline.com. You’re just joining Wi‑Fi, yet it keeps asking for your Microsoft 365 password. If any public Wi‑Fi ever demands your Microsoft 365 login, stop. Don’t type it. Use your phone’s hotspot or VPN instead, and report the venue Wi‑Fi to IT.

Attackers are compromising hotel and conference center Wi‑Fi gateways and changing DNS settings so business travelers are silently redirected to fake Microsoft…

Researchers reported an ongoing campaign where attackers compromise hotel and conference venue Wi‑Fi routers and quietly redirect visitors’ web traffic through…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…