07/27/2026
Attackers have been breaking into Wi-Fi gateways at hotels and conference venues and altering their DNS settings so guests get sent to fake Microsoft 365 sign-in pages instead of the real ones. ReliaQuest, which uncovered the campaign, says it’s been running since at least June and has hit compromised gateways in several U.S. cities plus India and Saudi Arabia. Victims span finance, legal, professional services, healthcare, energy, and retail — the researchers say that spread points to traveling employees being the target rather than any one industry. The activity resembles earlier router-hijacking campaigns tied to the Russian group APT28 (Fancy Bear).
How it works
Nobody’s confirmed how the attackers get in, but exposed management interfaces (SSH, SNMP, web admin) or unpatched vulnerabilities are the likely entry point. Once they have admin access, they repoint DNS to their own infrastructure. At least four lookalike domains have been registered for the phishing portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.
Some victims got a device-code authentication prompt instead. Approving it hands the attacker a valid OAuth token for a session they started — no password stolen, and MFA never comes into play.
In about a third of cases, the attackers also tried abusing WPAD, answering Windows’ automatic lookup with a malicious PAC file to push traffic through their own proxy. ReliaQuest couldn’t confirm whether that part worked.
Worth noting: setting DNS to 8.8.8.8 doesn’t help. The gateway intercepts the plain-text queries before they ever reach Google.
Defenses
Always-on, full-tunnel VPN
Encrypted DNS in strict mode
Disable WPAD
Turn off Device Code flow in Entra ID unless you actually need it
Review logs for anything unusual
At Rhinotech, we help businesses in Easley, SC, Canton, GA, and surrounding areas stay ahead of these risks with reliable managed IT support, robust cybersecurity solutions, and expert guidance tailored to small and mid-sized organizations. Whether it’s implementing stronger defenses, conducting security assessments, or ensuring your systems are up to date, our team is here to protect what matters most to you.
Stay secure! Visit us at https://rhinotech.io to learn more about how we can support your technology needs.