How Hackers Are Weaponizing Hotel Wi-Fi to Steal Corporate Microsoft 365 Accounts

Chronological Source Flow
Back

AI Fusion Summary

Threat actors are hijacking hotel Wi-Fi gateways to reroute business travelers to fake Microsoft 365 login pages, stealing corporate credentials. This attack utilizes DNS poisoning, AiTM, and Entra ID device-code flow to harvest data without leaving traces. ReliaQuest identified these tactics expanding into hospitality, potentially linked to FrostArmada or APT28. The operation targets executives through captive portals and WPAD, using specific IOCs like m365-owa.com to facilitate the hijacking of corporate sessions and sensitive account access.
Community Comments
Loading updates...
0