[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffoIlo3mqARqhLXT00ge-Kl5UIU8Tuz-nN-sErbd6ZVU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"befb5b4e-82ab-47cb-a892-5766375a3107","public-wi-fi-gateway-compromise-used-to-steal-m365-credentials-via-dns-hijacking","7def0654-c940-4731-9518-1eb420d82b8c","Public Wi-Fi Gateway Compromise Used to Steal M365 Credentials via DNS Hijacking","Attackers compromised public Wi-Fi gateway appliances at hotels and conference centers, modifying DNS configurations to silently redirect corporate travelers to attacker-controlled phishing infrastructure — a classic Adversary-in-the-Middle (AitM) attack. The root cause is a combination of poorly secured network appliances (default or weak credentials, unpatched firmware) and corporate employees authenticating to sensitive services like Microsoft 365 over untrusted networks without adequate protection. This matters because even MFA-protected accounts can be bypassed by AitM techniques that intercept session tokens in real time. The campaign's suspected link to APT28 (a Russian nation-state actor) underscores that corporate travelers are high-value targets, and the credentials harvested can enable espionage, data theft, or further lateral movement into enterprise environments.","**Immediate actions:**\n- Enforce phishing-resistant MFA (e.g., FIDO2\u002Fpasskeys) for all Microsoft 365 accounts to resist AitM session-token theft.\n- Issue a travel security advisory requiring employees to use a corporate VPN before connecting to any public or hotel Wi-Fi network.\n- Block legacy authentication protocols in Microsoft 365 that cannot enforce modern conditional access policies.\n\n**Long-term improvements:**\n- Implement Conditional Access policies that restrict M365 logins to managed, compliant devices and known corporate IP ranges.\n- Deploy a Zero Trust Network Access (ZTNA) solution so traveling employees never directly expose credentials over untrusted networks.\n- Establish a regular firmware patching and hardening programme for all network gateway appliances used at corporate facilities or partner venues.\n\n**Detection measures:**\n- Monitor Microsoft 365 sign-in logs for impossible travel events, unfamiliar IP geolocations, or token replay anomalies indicating AitM interception.\n- Enable Microsoft Entra ID Protection risk-based sign-in policies to automatically challenge or block suspicious authentication attempts.\n- Integrate threat intelligence feeds covering APT28\u002FFrostArmada infrastructure IOCs into your SIEM for early warning of campaign-related activity.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-63B: Digital Identity Guidelines (Phishing-Resistant AAL3)","NIST AC-17: Remote Access","NIST SC-20: Secure Name\u002FAddress Resolution Service","NIST SI-3: Malicious Code Protection","NIST SP 800-46: Guide to Enterprise Telework and Remote Access Security","MITRE ATT&CK T1557: Adversary-in-the-Middle","MITRE ATT&CK T1040: Network Sniffing","MITRE ATT&CK T1071.004: DNS Application Layer Protocol","ISO\u002FIEC 27001:2022 A.8.20: Networks Security","GDPR Article 32: Security of Processing (for EU traveler data at risk)","published","2026-07-27T12:21:33.311093+00:00","2026-07-27T12:21:33.206+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fwww.securityweek.com\u002Fhacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials\u002F","hacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials-8129ea","Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":41,"name":42,"slug":43,"description":44,"color":45},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":47,"name":48,"slug":49,"description":50,"color":51},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[53],{"id":54,"date":55,"edition":56,"title":57,"audio_url":58},"1a75dd05-f0a5-4490-9f6a-2141ec9a5496","2026-07-27","afternoon","ThreatNoir Afternoon Brief — July 27","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-27\u002Fthreatnoir-afternoon-brief-2026-07-27.mp3"]