CyberSecurity

Hotel Wi-Fi? Think Again. Hackers Are Poisoning Public Gateways to Steal Corporate Logins

Published

on

The New Travel Risk: Your Hotel’s Wi-Fi Gateway

That free Wi-Fi in the hotel lobby might be doing more than just checking you in. A new campaign is targeting the Microsoft 365 accounts of traveling corporate employees by compromising the very gateways that manage public internet access.

Security firm ReliaQuest has been tracking the activity since at least June 2026. The attackers aren’t setting up rogue hotspots. Instead, they’re breaking into the small office/home office (SOHO) routers that power captive portal networks at shared venues across the US, India, and Saudi Arabia.

The goal? Redirect unsuspecting users to attacker-controlled infrastructure designed to harvest their credentials.

How the Attack Unfolds

The hackers modify the DNS configurations of compromised routers. When a traveler connects to the hotel or conference center network and tries to browse the web, they’re silently sent to a malicious server.

From there, the attackers use an adversary-in-the-middle (AitM) technique. This allows them to intercept traffic in real time, capturing not just login credentials but other sensitive information as it flows between the user and legitimate services.

ReliaQuest identified four attacker-registered domains used in the campaign, all serving Microsoft-impersonation lures to trick victims into entering their work credentials.

Who’s Being Targeted

The firm observed traffic from organizations across financial services, professional services, legal, health care, energy, and retail. As ReliaQuest notes, this isn’t sector-specific targeting. It’s a campaign that goes after traveling employees wherever they connect.

That means airports, conference centers, healthcare facilities, universities, and event venues all face a similar attack surface. If you run captive Wi-Fi services, you’re in the crosshairs.

A Familiar Playbook with a Twisted Ending

The activity bears some resemblance to the previously documented FrostArmada campaign, which was attributed to APT28 — also known as Forest Blizzard and Fancy Bear. That group is believed to be linked to Russia’s General Staff Main Intelligence Directorate (GRU).

But there’s a key difference. The new attacks use DNS poisoning to redirect all users to attacker-controlled infrastructure. FrostArmada, by contrast, didn’t rely on this technique.

ReliaQuest suggests this could be “potentially an indicator of a less sophisticated or less careful actor than APT28.” The tactics, techniques, and procedures (TTPs) show the threat actor is at least reusing APT28’s tradecraft, but the overlap isn’t complete.

“The targeting of captive portal appliances — especially those used in hotels and conference centers — wasn’t previously documented in FrostArmada reporting,” ReliaQuest notes. “Attacker infrastructure also differed from prior FrostArmada activity. The domain registrations and IP addresses used don’t align with infrastructure previously seen in APT28 campaigns.”

What This Means for Security Teams

This campaign highlights a blind spot in many corporate security strategies. You can patch your endpoints, enforce multi-factor authentication, and train your staff on phishing emails — but you can’t control the Wi-Fi router at a Marriott in Mumbai.

For organizations with frequent travelers, the implications are serious. A single compromised login could give attackers a foothold in your Microsoft 365 environment, leading to data exfiltration, business email compromise, or worse.

Practical Defenses for Road Warriors

  • Use a VPN: A reputable VPN encrypts traffic before it hits the network, making DNS poisoning and AitM attacks far less effective.
  • Verify captive portals: Before entering credentials on any public Wi-Fi login page, double-check the URL and ensure it matches the venue’s official portal.
  • Enable phishing-resistant MFA: Hardware security keys or certificate-based authentication can stop credential theft even if passwords are compromised.
  • Monitor for anomalous logins: Watch for sign-ins from unusual locations or devices, especially for accounts belonging to frequent travelers.

The Bigger Picture: Public Wi-Fi Is a Persistent Threat

This isn’t the first time public Wi-Fi has been weaponized, and it won’t be the last. The Mirai botnet targeting flawed D-Link routers shows how vulnerable these devices can be. And China-linked APT groups expanding their backdoor arsenals suggest the threat landscape is only getting more complex.

For security leaders, the takeaway is clear: treat every public network as hostile. The convenience of hotel Wi-Fi isn’t worth handing over your corporate credentials to an unseen adversary.

As ReliaQuest’s findings demonstrate, the attackers are adapting. They’re finding new ways to exploit the trust we place in everyday technology. It’s time for defenders to adapt too.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version