Cybersecurity researchers have uncovered a sophisticated attack campaign where threat actors are compromising hotel Wi-Fi networks to hijack Microsoft 365 accounts without relying on traditional phishing methods. The hotel Wi-Fi DNS poisoning attacks target corporate travelers by exploiting vulnerabilities in captive portal infrastructure at hotels and conference centers.
According to ReliaQuest, the attack methodology represents a significant evolution in credential theft techniques. Unlike conventional attacks that depend on phishing emails, malicious attachments, or endpoint malware, these adversaries are directly compromising the Wi-Fi gateway infrastructure used by business travelers to intercept authentication attempts.
How Do the Attacks Target Hotel Networks?
The threat actors specifically target hotel and conference-center Wi-Fi gateways, poisoning DNS responses to redirect legitimate Microsoft 365 authentication requests. When corporate users connect to these compromised networks and attempt to access their accounts, the poisoned DNS entries route their credentials through attacker-controlled infrastructure without triggering typical security alerts.
This approach proves particularly effective because it bypasses most endpoint security solutions and user awareness training focused on identifying suspicious emails or links. The attack occurs at the network infrastructure level, making it largely invisible to the end user and difficult to detect with standard security tools.
What Connections Exist to Previous APT Campaigns?
ReliaQuest assesses that the tradecraft employed in these attacks closely mirrors previous campaigns attributed to APT28. The threat actors appear to be extending router compromise techniques previously associated with this advanced persistent threat group into the realm of captive-portal infrastructure commonly used in hospitality and business travel environments.
The targeting of business travelers represents a strategic choice, as corporate staff frequently connect to hotel Wi-Fi networks during conferences, meetings, and work trips. These environments provide attackers with access to high-value targets who may be authenticating to sensitive corporate resources while away from their organization’s protected network perimeter.
When Did This Campaign Begin?
Security researchers indicate that this threat activity has been ongoing since at least June 2026. The extended duration of the campaign suggests the attackers have successfully maintained access to compromised gateway infrastructure without detection for a considerable period.
The lack of traditional attack indicators such as phishing emails or malware makes these intrusions particularly challenging for security teams to identify and remediate. Organizations with mobile workforces face increased risk as their employees regularly connect to potentially compromised third-party network infrastructure during business travel.
Source: GBHackers Security