Public Wi-Fi Gateway Compromise Used to Steal M365 Credentials via DNS Hijacking
Attackers compromised public Wi-Fi gateway appliances at hotels and conference centers, modifying DNS configurations to silently redirect corporate travelers to attacker-controlled phishing infrastructure — a classic Adversary-in-the-Middle (AitM) attack. The root cause is a combination of poorly secured network appliances (default or weak credentials, unpatched firmware) and corporate employees authenticating to sensitive services like Microsoft 365 over untrusted networks without adequate protection. This matters because even MFA-protected accounts can be bypassed by AitM techniques that intercept session tokens in real time. The campaign's suspected link to APT28 (a Russian nation-state actor) underscores that corporate travelers are high-value targets, and the credentials harvested can enable espionage, data theft, or further lateral movement into enterprise environments.
Tactical Insight
Immediate actions
- Enforce phishing-resistant MFA (e.g., FIDO2/passkeys) for all Microsoft 365 accounts to resist AitM session-token theft.
- Issue a travel security advisory requiring employees to use a corporate VPN before connecting to any public or hotel Wi-Fi network.
- Block legacy authentication protocols in Microsoft 365 that cannot enforce modern conditional access policies.
Long-term improvements
- Implement Conditional Access policies that restrict M365 logins to managed, compliant devices and known corporate IP ranges.
- Deploy a Zero Trust Network Access (ZTNA) solution so traveling employees never directly expose credentials over untrusted networks.
- Establish a regular firmware patching and hardening programme for all network gateway appliances used at corporate facilities or partner venues.
Detection measures
- Monitor Microsoft 365 sign-in logs for impossible travel events, unfamiliar IP geolocations, or token replay anomalies indicating AitM interception.
- Enable Microsoft Entra ID Protection risk-based sign-in policies to automatically challenge or block suspicious authentication attempts.
- Integrate threat intelligence feeds covering APT28/FrostArmada infrastructure IOCs into your SIEM for early warning of campaign-related activity.