Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees.

Wi-Fi attack

A threat actor has been hacking public Wi-Fi gateway appliances at organizations running captive portal networks to compromise the Microsoft 365 accounts of traveling corporate employees, ReliaQuest reports.

As part of the attacks, the hackers modified the DNS configurations of the compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure for credential theft.

Ongoing since at least June 2026, the activity is similar to the previously observed FrostArmada campaign, which was attributed to APT28, also known as Forest Blizzard, and Fancy Bear, a state-sponsored group believed to be linked to Russia’s General Staff Main Intelligence Directorate (GRU).

Using the adversary-in-the-middle (AitM) technique, the hackers can intercept the victims’ traffic and harvest their credentials and other sensitive information.

The newly observed activity, ReliaQuest says, involved hacked Wi-Fi gateways at shared venues such as hotels and conference centers across the US, India, and Saudi Arabia.

The cybersecurity firm warns that any organization running captive Wi-Fi services, including airports, conference centers, healthcare facilities, universities, and event venues, faces a similar attack surface.

Advertisement. Scroll to continue reading.

“We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail—confirming this isn’t sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect,” ReliaQuest notes.

The cybersecurity firm identified four attacker-registered domains used as part of these attacks to deliver Microsoft-impersonation lures.

Unlike the FrostArmada campaign, the fresh attacks used DNS poisoning to redirect all users to attacker-controlled infrastructure, “potentially an indicator of a less sophisticated or less careful actor than APT28”, ReliaQuest says.

Overall, the tactics, techniques, and procedures (TTPs) observed in the new campaign suggest that the threat actor has been at least reusing APT28’s tradecraft, but do not fully overlap with FrostArmada.

“The targeting of captive portal appliances—especially those used in hotels and conference centers—wasn’t previously documented in FrostArmada reporting. Attacker infrastructure also differed from prior FrostArmada activity. The domain registrations and IP addresses used don’t align with infrastructure previously seen in APT28 campaigns,” ReliaQuest notes.

Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

Related: Mirai Botnet Targets Flaw in Discontinued D-Link Routers

Related: China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

Related: Armored Likho APT Targeting Government, Electric Power Entities

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.