A widespread DNS poisoning campaign is exploiting hotel Wi-Fi routers and conference venue networks to harvest corporate login credentials from business travelers, according to cybersecurity researchers. The attacks target public Wi-Fi infrastructure at hotels, conference centers and other hospitality venues frequently visited by corporate employees, with compromised devices identified across multiple US cities, India and Saudi Arabia.
How Are Attackers Compromising Hotel Wi-Fi Infrastructure?
ReliaQuest researchers revealed in a blog post published on July 23 that attackers gain initial access to Wi-Fi gateway devices by exploiting exposed management interfaces, including SSH, SNMP and web administration consoles. The campaign also leverages weak or reused administrator login credentials to penetrate these systems. Once inside, attackers modify router configurations to implement DNS poisoning, which redirects legitimate web traffic through attacker-controlled infrastructure.
This sophisticated approach allows credential theft without requiring phishing links, malicious attachments or direct interaction with victim devices. Users continue their normal online activities with no indication of compromise, while attackers silently monitor traffic and capture usernames, passwords and other sensitive information.
Who Is Behind This DNS Poisoning Campaign?
The tradecraft observed in this ongoing campaign shows similarities to previous operations attributed to APT28, also known as Fancy Bear and Forest Blizzard. This cyber espionage group has established links to the Russian military intelligence agency (GRU). By targeting venues known to host traveling corporate employees, the attackers can potentially harvest a wide range of credentials for accessing sensitive corporate information.
ReliaQuest researchers emphasized that while their investigation focused on compromised appliances primarily deployed at hotels running captive Wi-Fi services, any operator of captive portal networks faces similar risks. This includes airports, conference centers, co-working spaces, universities, healthcare facilities and event venues.
What Protection Measures Should Organizations Implement?
ReliaQuest issued several recommendations to prevent DNS poisoning attacks from reaching endpoints. Organizations should enforce always-on VPN with full-tunnel configuration, ensuring all DNS requests route through trusted corporate resolvers. IT teams should audit proxy authentication logs for connections from unknown hosts and suspicious activity from known abused infrastructure.
Additional protective measures include disabling web proxy auto-discovery (WPAD) where not required and training employees to validate URLs and certificates before entering credentials, particularly on public Wi-Fi networks. Organizations using Microsoft Entra ID should configure Conditional Access policies to block the device-code authentication flow at the identity provider level.
Source: Infosecurity Magazine