Hackers have been compromising Wi-Fi gateways at hotels and conference centers since June, redirecting users to fake Microsoft 365 login pages to steal credentials across multiple industries. Attackers modify DNS settings on vulnerable appliances through exposed management interfaces or weak credentials, registering domains like m365-owa.com to host phishing pages. Users attempting to access legitimate Microsoft portals land on attacker-controlled pages, enabling credential theft and session hijacking through device-code authentication flows that generate OAuth tokens, bypassing multi-factor authentication.
The campaign resembles FrostArmada operations attributed to Russian APT28, with compromised gateways observed in multiple U.S. cities, India, and Saudi Arabia. Using public DNS servers like Google's 8.8.8.8 does not prevent the attack since the gateway forges plain-text requests before reaching the resolver. The attackers also attempted WPAD abuse, though success remains unconfirmed.
ReliaQuest recommends using always-on full-tunnel VPNs with encrypted DNS in strict mode, disabling WPAD, and disabling Device Code authentication flow in Microsoft Entra ID when not needed. The campaign targets traveling employees across financial services, legal, healthcare, energy, and retail sectors. The attack demonstrates how network-level compromise can bypass endpoint security controls and MFA through legitimate authentication flows.
Read more...
