securityaffairs.com 7/26/2026, 2:08:23 PM · external

Hotel WiFi attacks hijack Microsoft 365 logins, linked to APT28

Hotel WiFi attacks hijack Microsoft 365 logins, linked to APT28
CyberSIXT Evidence Panel
Primary Source reliaquest.com
Threat Actor

HACKERS have been targeting hotel Wi-Fi networks to steal Microsoft 365 credentials by compromising Wi-Fi gateways. This tactic involves redirecting users to fake login pages without the need for phishing emails. The attackers gain access through weak or reused admin credentials on exposed management interfaces. Once compromised, they control DNS settings to direct traffic to fraudulent sites. Additionally, they exploit Windows' automatic proxy discovery feature (WPAD) to intercept broader network traffic.

This has been linked to a campaign associated with APT28, suggesting prior patterns of cyber espionage. Recommended defenses include enforcing always-on VPNs and disabling certain network features to mitigate risk.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline