Wi-Fi Attacks in Hotels: Hackers Target Microsoft 365 Accounts via Gateways
Security researchers from ReliaQuest have identified an ongoing cyber campaign specifically targeting business travelers at hotels and conference centers. In these attacks, cybercriminals compromise the infrastructure of Wi-Fi gateways to intercept and take over Microsoft 365 account credentials. These attacks have been observed across various regions and industries, raising alarms about the vulnerabilities associated with public Wi-Fi networks.
Weak Credentials as Gateways
According to findings by ReliaQuest, attackers exploit vulnerabilities in so-called captive portal devices—interfaces that users typically encounter when logging into public or semi-private networks. Access to these devices is often gained through weak administrator credentials, particularly via protocols like SSH or SNMP, as well as through web-based configuration consoles.
Once control over a gateway is obtained, attackers utilize DNS poisoning techniques. This allows them to redirect user traffic selectively. Instead of connecting to legitimate services, victims are led to fake login pages for Microsoft 365. Four specific malicious domains have been identified in this context: m365-owa.com, owa-ms365.com, ms365-device.com, and ms365-live.com.
Bypassing Multi-Factor Authentication
A central feature of this campaign is the misuse of the so-called Device Code Flow. This function is initially intended for registering devices with cloud services that lack an easy input method. However, attackers hijack this process to bypass security measures like Multi-Factor Authentication (MFA).
Additionally, researchers observed that around one-third of the analyzed cases involved abuse of the Web Proxy Auto-Discovery (WPAD) protocol. The technical characteristics and tactics utilized are reportedly similar to those of the infamous APT28 group, also known as Fancy Bear or FrostArmada, which has historically targeted high-profile organizations.
Affected Regions and Industries
The campaign has been active since June 2026, with geographic hotspots in the USA, India, and Saudi Arabia. The attacks are not limited to a single industry but have affected various sectors, including finance and law, healthcare, energy, and retail.
Specific IP addresses associated with the attackers’ infrastructure have also been identified: 38.146.28.75, 31.57.243.154, and 104.194.159.150.
Recommended Protective Measures for Businesses
Given the sophistication and professionalism of these attacks, experts recommend enhanced security precautions for employees on business trips. Key measures include the consistent use of full-tunnel VPN connections, which encrypt all data traffic and protect against local network manipulations.
Furthermore, it is advisable to implement encrypted DNS and to disable the WPAD protocol on corporate devices. To mitigate the specific account takeover methods, organizations should also consider blocking the Device Code Flow in their cloud security policies unless it is essential for business operations.
By implementing these measures and maintaining vigilance, companies can significantly reduce their risk of falling victim to these targeted cyber attacks.

