A cybersecurity alert highlights ongoing attacks where threat actors compromise public Wi-Fi gateways to target traveling corporate employees' Microsoft 365 accounts. The attackers employ DNS poisoning to redirect users to fraudulent sites for credential theft, a method similar to the FrostArmada campaign linked to APT28 (a Russian state-sponsored group). This activity affects various sectors, including financial services and healthcare, indicating broad targeting.
The attackers have distinguished themselves by using less sophisticated techniques than APT28 and have been found using specific domains to deliver Microsoft-impersonating lures. The campaign particularly threatens organizations providing public Wi-Fi, such as hotels and airports, signaling a need for increased security measures.