Back to Feed
Identity & AccessJul 27, 2026

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

Threat actor hacks public Wi-Fi gateways to steal Microsoft 365 credentials from traveling corporate employees.

Summary

A threat actor has been compromising public Wi-Fi gateway appliances at hotels, conference centers, and other shared venues across the US, India, and Saudi Arabia to target Microsoft 365 accounts of traveling corporate employees. The attackers modified DNS configurations to redirect users to attacker-controlled infrastructure for credential harvesting using adversary-in-the-middle (AitM) techniques. The campaign, ongoing since at least June 2026, shares similarities with the FrostArmada campaign attributed to APT28 (Forest Blizzard/Fancy Bear), though infrastructure and targeting methods differ, suggesting either a copycat actor or a related group using similar tradecraft.

Full text

A threat actor has been hacking public Wi-Fi gateway appliances at organizations running captive portal networks to compromise the Microsoft 365 accounts of traveling corporate employees, ReliaQuest reports. As part of the attacks, the hackers modified the DNS configurations of the compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure for credential theft. Ongoing since at least June 2026, the activity is similar to the previously observed FrostArmada campaign, which was attributed to APT28, also known as Forest Blizzard, and Fancy Bear, a state-sponsored group believed to be linked to Russia’s General Staff Main Intelligence Directorate (GRU). Using the adversary-in-the-middle (AitM) technique, the hackers can intercept the victims’ traffic and harvest their credentials and other sensitive information. The newly observed activity, ReliaQuest says, involved hacked Wi-Fi gateways at shared venues such as hotels and conference centers across the US, India, and Saudi Arabia. The cybersecurity firm warns that any organization running captive Wi-Fi services, including airports, conference centers, healthcare facilities, universities, and event venues, faces a similar attack surface.Advertisement. Scroll to continue reading. “We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail—confirming this isn’t sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect,” ReliaQuest notes. The cybersecurity firm identified four attacker-registered domains used as part of these attacks to deliver Microsoft-impersonation lures. Unlike the FrostArmada campaign, the fresh attacks used DNS poisoning to redirect all users to attacker-controlled infrastructure, “potentially an indicator of a less sophisticated or less careful actor than APT28”, ReliaQuest says. Overall, the tactics, techniques, and procedures (TTPs) observed in the new campaign suggest that the threat actor has been at least reusing APT28’s tradecraft, but do not fully overlap with FrostArmada. “The targeting of captive portal appliances—especially those used in hotels and conference centers—wasn’t previously documented in FrostArmada reporting. Attacker infrastructure also differed from prior FrostArmada activity. The domain registrations and IP addresses used don’t align with infrastructure previously seen in APT28 campaigns,” ReliaQuest notes. Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Related: Mirai Botnet Targets Flaw in Discontinued D-Link Routers Related: China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors Related: Armored Likho APT Targeting Government, Electric Power Entities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire StrongestLayer Raises $4.1 Million in Seed Funding ExtensionEndpoint Security Firm Glow Launches With $180M in Funding at $1.2B ValuationEmpirical Security Raises $25 Million in Series A FundingNew HollowGraph Malware Abuses Microsoft 365 Calendar for C&C CommunicationEstée Lauder Discloses Impact From Oracle EBS Zero-Day HackClover Health Investments Discloses Data BreachZimbra Update Patches Critical VulnerabilitiesOpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Latest News Coca-Cola Confirms Data Breach After Fairlife Ransomware AttackBeelzebub Raises $3.4 Million for Hacker-Trapping PlatformWhat’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find OutAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on ExploitsDentaQuest Data Breach Potentially Impacts Over 23 Million PeopleMCBS Data Breach Affects 1.2 Million IndividualsRockwell Patches Code Execution Flaws in Arena Simulation SoftwareIn Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveBarry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — FrostArmada
  • mitre_attack — T1187
  • mitre_attack — T1557

Entities

APT28 (threat_actor)Forest Blizzard (threat_actor)Fancy Bear (threat_actor)FrostArmada (campaign)Microsoft 365 (product)ReliaQuest (vendor)