Hotel Wi-Fi hijack campaign quietly harvests Microsoft 365 logins from business travellers

A cluster with overlaps to Russia-linked APT28 activity is tampering with DNS on hotel and conference Wi-Fi gateways to funnel guests into fake Microsoft login pages, ReliaQuest reports.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal news-editorial image of a dimly lit security operations centre at night, rows of large curved monitors glowing blue and amber with abstract
Share

Key points

  • ReliaQuest has tracked a campaign hijacking Wi-Fi gateways at hotels and conference venues since at least June 2024, redirecting guests to fake Microsoft 365 sign-in pages.
  • Compromised gateways have been spotted in multiple US cities, plus India and Saudi Arabia, hitting finance, legal, healthcare, energy and retail visitors.
  • The attackers registered at least four lookalike domains, including m365-owa[.]com and ms365-live[.]com, to host the phishing pages.
  • A device-code trick lets the attackers get in even when the victim has multi-factor authentication switched on.
  • ReliaQuest assesses with medium confidence that the activity overlaps with FrostArmada router operations linked to APT28 (also tracked as Fancy Bear or Forest Blizzard by Microsoft).

Someone has been quietly rewiring the Wi-Fi at hotels and conference centres so that business travellers who try to log into Microsoft 365 end up on a fake page instead.

The campaign, first reported by BleepingComputer and detailed by security firm ReliaQuest, has been running since at least June. It targets the Wi-Fi gateways that guests connect to, not the guests' own laptops.

How does the attack actually work?

The hackers break into the Wi-Fi gateway itself, the box that hands out internet access in the lobby or the conference hall, and change its DNS settings. DNS is the internet's phone book: it turns a name like login.microsoftonline.com into the numeric address your laptop actually connects to.

With the phone book rewritten, a guest who types the real Microsoft address into their browser is quietly sent to a copycat page controlled by the attackers. ReliaQuest says the crew registered at least four lookalike domains for this: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com and ms365-live[.]com.

It is not yet clear how the attackers get onto the Wi-Fi gateways in the first place. ReliaQuest suggests exposed admin interfaces (SSH, SNMP or web dashboards left open to the internet) or unpatched flaws in the appliances themselves.

Does multi-factor authentication stop this?

Not on its own. In some cases the attackers use what is called a device-code flow, a legitimate Microsoft feature that lets you sign in on a device without a keyboard by approving a prompt.

The fake page shows the victim a real-looking Microsoft prompt. Approving it does not log the victim in. It logs the attacker in, on their own computer, with a valid session token issued by Microsoft. No password is stolen and no MFA code is intercepted, because the criminal never needed either.

Who is behind it?

ReliaQuest assesses with medium confidence that the tradecraft overlaps with FrostArmada, a router-focused campaign attributed to the Russian military intelligence group APT28. Microsoft tracks the same cluster as Forest Blizzard, and it is also known as Fancy Bear.

Attribution here is a capability-and-TTP match, not a signed confession. Targeting travelling staff through hospitality Wi-Fi fits APT28's known interest in intelligence collection, but ReliaQuest stops short of a hard call.

Detail What ReliaQuest found
Campaign start At least June 2024
Regions seen US cities, India, Saudi Arabia
Sectors touched Finance, legal, healthcare, energy, retail, professional services
Phishing domains m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, ms365-live[.]com
Suspected cluster Overlaps with APT28 / Forest Blizzard (medium confidence)

In roughly a third of cases the attackers also poked at Web Proxy Auto-Discovery, a Windows feature that automatically looks for a proxy server. By answering that lookup with a malicious config file, they could in theory route traffic through their own server. ReliaQuest could not confirm this worked in practice.

What should travelling staff do?

Switching to a public DNS like 8.8.8.8 will not save you here, because the compromised gateway intercepts the request before it ever leaves the building. ReliaQuest recommends an always-on VPN that tunnels all traffic, encrypted DNS in strict mode, and turning off device-code sign-in in Microsoft Entra ID where it is not needed.

For most business travellers the practical advice is smaller: connect through your phone's hotspot for anything sensitive, and treat any Microsoft login prompt on hotel Wi-Fi with suspicion.

© 2026 Threat Vectr