APT29 Hijacks Public Wi-Fi Gateways to Steal M365 Credentials from Traveling Employees
Russian state-sponsored threat actor APT29 (Storm-2945/Midnight Blizzard) compromised public Wi-Fi captive portals at hotels and conference venues to intercept and manipulate traffic for traveling employees. By poisoning DNS and HTTP responses, attackers redirected users to fake browser update pages delivering Golang-based remote access trojans, while simultaneously exploiting device code phishing to hijack Microsoft 365 authentication sessions. This attack is particularly dangerous because employees instinctively trust hotel and conference Wi-Fi, and the attack surface is difficult for organizations to control since it exists entirely outside their network perimeter. The campaign underscores that credential theft no longer requires breaching corporate infrastructure — nation-state actors are increasingly targeting the weakest link: untrusted third-party networks used by traveling staff.
Tactical Insight
Immediate actions
- Require all remote and traveling employees to use a corporate VPN before connecting to any public or hotel Wi-Fi network.
- Enforce phishing-resistant MFA (e.g., FIDO2/hardware security keys) for all Microsoft 365 and cloud service accounts to neutralize device code phishing.
- Block or restrict device code flow authentication in Azure AD/Entra ID conditional access policies for users flagged as traveling or high-risk.
Long-term improvements
- Deploy a Zero Trust Network Access (ZTNA) architecture so that network location — including untrusted Wi-Fi — is never implicitly trusted for any resource access.
- Establish a mobile device management (MDM) policy that prevents installation of software or browser updates outside of approved enterprise channels.
- Conduct regular security training specifically covering the risks of public Wi-Fi, captive portals, and social-engineering lures disguised as browser updates.
Detection measures
- Monitor Microsoft 365 and Entra ID sign-in logs for anomalous device code authentication attempts or logins from unexpected geolocations.
- Deploy endpoint detection and response (EDR) tooling capable of identifying Golang-based RAT behavior and unauthorized outbound C2 connections.
- Alert on DNS resolution anomalies and unexpected certificate changes when employees connect from off-network locations.