bleeping-computer · Crawled Jul 24, 2026

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

4 IoCs 1 Actors
Read original article ↗

AI Summary

Hackers are hijacking hotel and conference center Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages, enabling theft of credentials and bypassing multi-factor authentication via OAuth token authorization. The campaign, active since at least June 2026, targets traveling employees across multiple sectors including finance, healthcare, and legal services. The attack technique resembles previous router-based campaigns linked to the APT28 group. Researchers observed malicious domains and attempted abuse of WPAD for traffic interception.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 4 extracted

Type Value Detail
Domain m365-owa[.]com Details →
Domain owa-ms365[.]com Details →
Domain ms365-device[.]com Details →
Domain ms365-live[.]com Details →

MITRE ATT&CK TTPs 11 techniques