bleeping-computer · Crawled Jul 24, 2026
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
4 IoCs 1 Actors
Read original article ↗
AI Summary
Hackers are hijacking hotel and conference center Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages, enabling theft of credentials and bypassing multi-factor authentication via OAuth token authorization. The campaign, active since at least June 2026, targets traveling employees across multiple sectors including finance, healthcare, and legal services. The attack technique resembles previous router-based campaigns linked to the APT28 group. Researchers observed malicious domains and attempted abuse of WPAD for traffic interception.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 4 extracted
MITRE ATT&CK TTPs 11 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1071.004 DNS · Command And Control T1078.004 Cloud Accounts · Defense Evasion T1090 Proxy · Command And Control T1114 Email Collection · Collection T1204.002 Malicious File · Execution T1556.005 Reversible Encryption · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access