In a sophisticated and wide-reaching cyberattack campaign that has been active since at least June, threat actors are exploiting compromised Wi-Fi networks in hotels and conference centers to redirect users to deceptive Microsoft 365 login pages. This tactic, identified by cybersecurity firm ReliaQuest, aims to steal corporate credentials, granting attackers access to sensitive business data, communications, and private documents. The campaign’s broad impact across various industries and geographical locations underscores a significant, evolving threat to mobile professionals and the organizations they represent.
The modus operandi involves manipulating the Domain Name System (DNS) settings of Wi-Fi gateways within hospitality and event venues. By altering these settings, attackers can intercept traffic intended for legitimate Microsoft 365 services, such as Outlook Web Access (OWA) or other Microsoft login portals. Instead of reaching the intended secure servers, users are rerouted to meticulously crafted phishing pages designed to mimic the official Microsoft interface, tricking unsuspecting individuals into entering their usernames and passwords.
ReliaQuest researchers have pinpointed compromised Wi-Fi gateways in multiple U.S. cities, alongside international locations including India and Saudi Arabia. This widespread geographical distribution suggests a well-organized and resourced threat actor, not confined by national borders. The campaign’s victims span a diverse array of sectors, including financial services, professional services, legal, healthcare, energy, and retail. This broad targeting indicates that the attackers are not focused on a specific industry but rather on any traveling employee who connects to compromised public Wi-Fi, highlighting the pervasive nature of the threat.
"We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail- confirming this isn’t sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect," a spokesperson for ReliaQuest stated in a recent advisory. This observation reinforces the notion that the attackers are leveraging a common vulnerability in public Wi-Fi infrastructure to achieve broad access.
The Evolving Threat Landscape of Wi-Fi Interception
The use of compromised Wi-Fi networks for credential harvesting is not a new phenomenon, but the sophistication and scale of this particular campaign are noteworthy. Traditionally, attackers might have relied on setting up rogue access points or exploiting unpatched vulnerabilities on individual devices. However, this new wave of attacks targets the network infrastructure itself, offering a more efficient and far-reaching method of compromise. By gaining control of the Wi-Fi gateway, attackers can affect multiple users simultaneously without requiring individual device exploitation.
The implications of such a breach are severe. Microsoft 365 is a cornerstone of modern business operations, housing vast amounts of sensitive data, including confidential client information, financial records, intellectual property, and internal communications. A successful credential theft could lead to unauthorized access, data exfiltration, business disruption, reputational damage, and significant financial losses. For organizations in sectors like financial services and healthcare, where data privacy and security are paramount, the consequences could be particularly dire, potentially leading to regulatory fines and loss of customer trust.

A Chronology of Compromise and Detection
While the precise initiation date of this campaign remains difficult to pinpoint, ReliaQuest’s analysis indicates that it has been actively ongoing since at least June of the current year. This suggests a sustained effort by the threat actors to infiltrate and maintain control over Wi-Fi infrastructure. The detection of compromised gateways in various regions over several months points to a persistent and evolving threat.
The initial discovery was made by ReliaQuest’s security intelligence team, who observed unusual traffic patterns and identified compromised Wi-Fi gateways. Their subsequent investigation meticulously mapped the attack chain and the infrastructure used by the threat actors. The firm’s findings were published to alert organizations and provide actionable defense recommendations.
The researchers have drawn parallels between this campaign and previous "router-based campaigns" such as FrostArmada, which were attributed to the Russian state-sponsored espionage group APT28, also known as Fancy Bear or Forest Blizzard. This attribution, while not definitive for the current campaign, suggests a potential connection to sophisticated, state-level actors with a history of conducting espionage and disruptive cyber operations. Such actors typically possess the resources and expertise to develop and deploy advanced attack methodologies.
Deconstructing the Attack Chain
The initial access vector for compromising the Wi-Fi gateways remains somewhat obscured. However, ReliaQuest posits that the threat actors likely gained administrator privileges through one of several common methods:
- Weakly Protected Management Interfaces: Many network devices, especially those in public-facing environments, might have their management interfaces (such as SSH, SNMP, or web admin dashboards) exposed to the internet with weak or default credentials. Attackers can systematically scan for and exploit these vulnerabilities.
- Exploitation of Vulnerabilities: Unpatched or zero-day vulnerabilities within the gateway’s firmware or software could also provide a pathway for attackers to gain unauthorized access.
Once administrative control is established, the attackers can then proceed to modify the gateway’s DNS settings. This is a critical step, as it allows them to redirect traffic for legitimate domains to their own controlled infrastructure. ReliaQuest has identified at least four domains registered by the attackers specifically for hosting these fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. The similarity and suggestive nature of these domain names are designed to appear legitimate to users who may not scrutinize the URL closely.
The user experience is designed to be seamless and deceptive. When a user attempts to access a legitimate Microsoft 365 service, their request is intercepted at the gateway. Instead of being routed to Microsoft’s servers, it is directed to one of the attacker-controlled domains. The fake login page presented is an exact replica of the official Microsoft 365 login screen, complete with branding and input fields for username and password. Believing they are interacting with a legitimate service, users willingly provide their credentials.
Bypassing Multi-Factor Authentication: The Device Code Flow
A particularly alarming aspect of this campaign is the attackers’ ability to bypass Multi-Factor Authentication (MFA) in certain scenarios. While many organizations have implemented MFA as a crucial layer of security, this attack demonstrates a sophisticated method to circumvent it. In some observed cases, users were directed to a fake Microsoft page presenting a device-code authentication flow.

This process typically involves a user being prompted to enter a code displayed on one device into another device or a web portal to authenticate a session. In this phishing scenario, approving the prompt on the user’s device actually authorizes a session initiated by the attacker. "What the user can’t see is that approving the prompt authorizes a session initiated by the attacker," ReliaQuest explained. This authorization results in a legitimate OAuth token being issued to the attacker’s client. Crucially, this process does not require the attacker to steal the user’s password or intercept access tokens directly; instead, they leverage the user’s own authorized action to gain access. This technique is highly effective as it leverages the legitimate authentication mechanisms of Microsoft 365, making it difficult to distinguish from a genuine authentication event.
Further Exploitation Tactics: WPAD Abuse
In approximately one-third of the investigated cases, the threat actors also attempted to leverage Web Proxy Auto-Discovery (WPAD) to further compromise victim environments. WPAD is a protocol that allows Windows clients to automatically discover proxy server settings. The attackers would respond to Windows’ automatic WPAD lookup with a malicious proxy auto-configuration (PAC) file.
The theoretical outcome of a successful WPAD attack is that all traffic from Windows applications, including web browsers like Chrome, would be routed through an attacker-controlled proxy. This would grant the attackers a man-in-the-middle position, allowing them to intercept, inspect, and potentially modify all network traffic originating from the compromised devices. While ReliaQuest could not confirm the success of these WPAD-based attacks, the attempt itself indicates a multi-pronged approach to maximizing compromise.
It is important to note that even the use of public DNS servers, such as Google’s 8.8.8.8, offers no protection against this specific attack vector. The DNS requests are forged at the gateway level before they are sent to the resolver. This means that the redirection occurs locally on the compromised network, irrespective of the external DNS server used.
Supporting Data and Industry Impact
The breadth of industries affected underscores the universality of the threat to mobile workforces. Financial institutions, for example, handle highly sensitive customer data and are prime targets for financial fraud and data theft. Legal firms store confidential client case details and proprietary information. Healthcare organizations manage protected health information (PHI), which is subject to stringent privacy regulations like HIPAA. Energy and retail sectors also deal with critical operational data and customer information.
The ongoing nature of the campaign, spanning several months, suggests a persistent threat actor with significant resources and operational capabilities. The identification of compromised gateways in multiple countries highlights the global reach of modern cyber threats and the interconnectedness of the digital landscape. The financial implications for affected organizations can be substantial, ranging from the direct costs of incident response and recovery to potential regulatory fines, loss of business, and damage to reputation.
Official Responses and Mitigation Strategies
In response to the findings, ReliaQuest has provided a series of recommendations for organizations to bolster their defenses against such attacks:

- Always-On, Full-Tunnel VPN: Implementing a VPN that routes all internet traffic through a secure, trusted corporate network can effectively bypass compromised public Wi-Fi. A full-tunnel VPN ensures that even DNS requests are routed securely.
- Encrypted DNS in Strict Mode: Utilizing DNS over HTTPS (DoH) or DNS over TLS (DoT) in strict mode can help ensure that DNS requests are encrypted and validated, preventing tampering.
- Disable WPAD: Organizations should consider disabling WPAD on their networks, especially for client devices, to prevent potential abuse of the protocol.
- Log Review and Monitoring: Regular review of network and security logs for suspicious activity, such as unusual DNS queries, unexpected gateway configurations, or failed authentication attempts, is crucial for early detection.
- Disable Device Code Authentication (When Not Needed): For Microsoft 365 environments, disabling the device code authentication flow in Microsoft Entra ID when it is not a business requirement can mitigate the risk of attackers exploiting this specific MFA bypass technique.
While there has been no direct public statement from Microsoft regarding this specific campaign, the company consistently advises users to be vigilant about phishing attempts and to enable MFA. The observed attack leverages legitimate authentication flows, making it a sophisticated challenge that requires a multi-layered security approach.
Broader Impact and Future Implications
This campaign serves as a stark reminder of the persistent threats lurking on public Wi-Fi networks, which are often assumed to be safe but can be fertile ground for attackers. The ability to compromise network infrastructure, rather than individual devices, represents a significant escalation in the sophistication of these attacks.
The reliance on stolen credentials, even with MFA bypassed, highlights the ongoing importance of robust identity and access management (IAM) practices. Organizations must not only implement strong authentication mechanisms but also educate their employees about the risks of phishing and social engineering.
The potential attribution to state-sponsored actors raises concerns about the broader geopolitical implications. Such campaigns can be used for espionage, disruption, or to lay the groundwork for more significant cyber operations. As the world becomes increasingly reliant on cloud services and mobile connectivity, the security of the underlying network infrastructure, particularly in public spaces, will become an ever more critical battleground in cybersecurity. The ReliaQuest findings are a call to action for organizations to re-evaluate their network security posture, especially for employees who travel frequently and rely on public Wi-Fi.







