Hackers are compromising hotel and conference center Wi-Fi gateways to alter DNS settings and redirect users to fake Microsoft 365 login pages, with activity linked to multiple regions and industries. ReliaQuest says the campaign may resemble FrostArmada operations tied to APT28, and it can bypass MFA through device-code phishing and malicious proxy tricks. #Microsoft365 #ReliaQuest #FrostArmada #APT28
Keypoints
- Attackers are changing DNS settings on compromised Wi-Fi gateways.
- Victims are redirected to fake Microsoft 365 login pages.
- The campaign has affected multiple industries and global locations.
- ReliaQuest links the activity to FrostArmada-style operations and APT28.
- The attackers may bypass MFA using device-code prompts and WPAD abuse.