Infosecurity-Magazine
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting multiple U.S. cities and regions in India and Saudi Arabia. Attackers redirect users to fake Microsoft login pages without requiring phishing emails or malware on devices. Cybersecurity firm ReliaQuest identified the threat, linking it to the Russian state-sponsored group APT28. The compromised gateways exploit weak management interfaces to alter DNS settings, enabling credential harvesting from unsuspecting users. Organizations across various sectors, including finance and healthcare, are at risk as employees connect to these networks. Recommendations include enforcing always-on, full-tunnel VPNs to mitigate the attack vector.
Key Points: • Attackers hijack hotel Wi-Fi to redirect users to fake Microsoft login pages. • The campaign has been active since June 2026, affecting multiple regions globally. • ReliaQuest links the attack to the Russian group APT28, emphasizing the need for VPN usage.