Monday, September 7, 2026

Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing

Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required.

ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff.

Since at least June 2026, threat actors have been compromising captive-portal appliances at hotels, conference centers, and other public Wi-Fi venues and using them to redirect all web traffic through attacker-controlled infrastructure.

Once the gateway is under their control, the adversary forges DNS responses so that requests for legitimate Microsoft domains resolve to attacker-operated hosts such as m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com, hosted on 31.57.243[.]154 and 104.194.159[.]150.

ReliaQuest observed victims connecting from multiple U.S. cities and internationally in India and Saudi Arabia, across financial services, legal, health care, energy, retail, and professional services indicating broad opportunistic targeting of traveling employees rather than sector-specific operations.

ReliaQuest assesses with low-to-medium confidence that initial access relies on exposed management interfaces on captive-portal gateways SSH, SNMP, and web administration consoles combined with weak or reused administrative credentials.

This methodology is consistent with router-targeting patterns documented in the FrostArmada campaign, in which APT28 (Forest Blizzard/Fancy Bear) compromised SOHO routers and modified DNS settings to harvest Microsoft 365 credentials and OAuth tokens via adversary-in-the-middle (AiTM) proxies.

The hotel Wi-Fi campaign repeats several FrostArmada hallmarks: gateway-level DNS hijacking, Microsoft-authentication domain targeting, and downstream AiTM-style Microsoft 365 account compromise.

As in FrostArmada, DNS manipulation turns otherwise routine login flows into credential and token theft paths, with traffic quietly proxied through attacker-controlled infrastructure.

ReliaQuest has identified a widespread campaign in which threat actors expanded DNS poisoning credential-harvesting techniques previously observed on small office/home office (SOHO) routers in activity attributed to “APT28”.

DNS poisoning attack flow (Source : ReliaQuest).
DNS poisoning attack flow (Source : ReliaQuest).

Where this campaign diverges is significant for defenders. First, the primary target is hospitality and conference captive-portal appliances, not consumer-grade SOHO routers, placing the attack surface directly at the point where corporate users routinely connect while traveling.

Second, the attacker’s domain registrations and IP blocks differ from previously reported APT28 infrastructure.

Hotel Wi-Fi DNS Poisoning Attacks

The DNS behavior is blunt: rather than selectively redirecting based on keywords, the poisoned gateways resolve all DNS requests to malicious infrastructure, suggesting a less discriminating operator or a different mission profile.

Once the adversary acquires administrative access to a captive-portal gateway, they gain effective control of DNS for every device that joins that network.

Because the gateway is the DHCP-assigned resolver, it can silently forge responses for queries to any domain and redirect users to attacker-hosted impersonation pages without altering endpoints.

ReliaQuest reports forged responses mapping requests like microsoft.commicrosoft.commicrosoft.com and login.microsoftonline[.]com to attacker IPs such as 38.146.28[.]75, where Microsoft 365-like login experiences are served to capture authentication artifacts or drive device-code abuse flows.

Common endpoint-centric DNS protections do not reliably stop this scenario. Hard-coding public resolvers such as 8.8.8[.]8 still leaves unencrypted DNS traffic visible and mutable at the gateway.

Opportunistic DNS-over-HTTPS/TLS implementations that allow plaintext fallback are likewise vulnerable; the gateway simply forces or hijacks the fallback and forges responses.

ReliaQuest emphasizes that only two configurations reliably break the chain: enforced full-tunnel VPN that ensures all DNS transits the corporate network, and strict-mode encrypted DNS (DoH/DoT with plaintext disabled).

Secondary techniques further broaden exposure. In roughly one-third of observed cases, the attacker attempted to exploit Web Proxy Auto-Discovery (WPAD) to route Windows and macOS application traffic through a malicious proxy, using DHCP option 252 and a forged DNS “wpad” record to deliver a hostile PAC file.

If successful, this shifts Chrome, Microsoft 365 clients, and other enterprise applications onto attacker-controlled proxies, where authentication flows can be inspected or manipulated under the guise of normal HTTPS traffic.

ReliaQuest also documented abuse of Microsoft’s device-code authentication flow on ms365-live[.]com, enabling attackers to gain OAuth tokens and MFA-satisfied access without directly stealing passwords.

Device-code flow is already recognized by Microsoft and independent researchers as high-risk, particularly in unmanaged or phishing scenarios, and can be explicitly blocked via Conditional Access policies in Microsoft Entra ID.

DOM content observed on ms365-device[.]com suggests an operator panel used to stage and rotate lures, track telemetry, and selectively gate content via IP allowlists indicating the campaign remains active and under ongoing management.

ReliaQuest’s core assessment is stark: organizations that enforce always-on, full-tunnel VPN on corporate devices are effectively protected against this specific gateway DNS poisoning technique because all traffic, including DNS, routes through trusted corporate resolvers before it can be intercepted by hostile infrastructure.

For environments where device-code flow is not operationally required, turning it off at the identity provider via Entra ID Conditional Access eliminates an increasingly popular account-compromise path.

Beyond configuration changes, ReliaQuest advocates multi-layered visibility across DNS, authentication, and endpoint behavior, using platforms such as GreyMatter Transit to detect anomalous DNS resolutions and sign-in routing in near real time and correlate signals that appear benign in isolation.

Their detection content focuses on attacker-registered domains and suspicious IPs, while automated response playbooks isolate affected hosts, disable exposed accounts, terminate active sessions, and delete attacker-enrolled devices from Entra ID to cut off durable access channels.

For security teams, the takeaway is that public Wi-Fi remains structurally untrusted and that DNS at the gateway is now a first-class attack surface for Microsoft 365 compromise.

Organizations that rely on traveling staff should treat always-on full-tunnel VPN, strict encrypted DNS, WPAD hardening, and device-code flow controls as baseline requirements rather than optional hardening.

IOCs

IOCsDescription
38.146.28[.]75DNS poisoning response IP address
31.57.243[.]154DNS poisoning response IP hosting ms365-device[.]com,owa-ms365[.]com and m365-owa[.]com
m365-owa[.]comAttacker controlled domain
owa-ms365[.]comAttacker controlled domain
ms365-device[.]comAttacker controlled domain
ms365-live[.]comAttacker controlled domain
104.194.159[.]150IP address of ms365-live[.]com
chikolimdrid[at]gmail[.]comRegistrant email of the attacker domains

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What Features Should AI SOC Have in 2026? A Complete Checklist Download the AI SOC Features Checklist

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services...

OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure

OpenAI has announced a $1 billion global commitment to...

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines...

The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced

Best value overall: Ubiquiti. Published hardware pricing, no mandatory...

The 12 Best Network Sandboxing Solutions, Compared and Priced

Best value overall: ANY.RUN. It publishes its pricing, offers...

Related Articles

Recent News