{"id":17142,"date":"2026-07-27T15:15:53","date_gmt":"2026-07-27T15:15:53","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17142"},"modified":"2026-07-27T15:15:53","modified_gmt":"2026-07-27T15:15:53","slug":"hackers-compromise-lodge-wi-fi-gateways-to-hijack-microsoft-365-accounts","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17142","title":{"rendered":"Hackers Compromise Lodge Wi-Fi Gateways to Hijack Microsoft 365 Accounts"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<style><![CDATA[\n#ar-widget{margin:0 0 2rem;font-family:-apple-system,BlinkMacSystemFont,\"Segoe UI\",sans-serif;}\n#ar-widget .ar-box{background:#fff;border:1px solid #e5e7eb;border-radius:12px;padding:1.1rem 1.4rem;}\n#ar-widget .ar-top{display:flex;align-items:center;gap:10px;margin-bottom:.85rem;}\n#ar-widget .ar-icon-wrap{width:38px;height:38px;border-radius:50%;background:#EEEDFE;display:flex;align-items:center;justify-content:center;flex-shrink:0;}\n#ar-widget .ar-meta{flex:1;min-width:0;}\n#ar-widget .ar-label{font-size:10px;color:#9ca3af;text-transform:uppercase;letter-spacing:.06em;margin:0 0 2px;}\n#ar-widget .ar-title-text{font-size:13px;font-weight:600;margin:0;color:#111827;white-space:nowrap;overflow:hidden;text-overflow:ellipsis;}\n#ar-widget .ar-progress-section{margin-bottom:.7rem;}\n#ar-widget #ar-seek{width:100%;height:4px;accent-color:#534AB7;cursor:pointer;display:block;margin:0;-webkit-appearance:none;appearance:none;background:#e5e7eb;border-radius:2px;outline:none;border:none;}\n#ar-widget #ar-seek::-webkit-slider-thumb{-webkit-appearance:none;width:14px;height:14px;border-radius:50%;background:#534AB7;cursor:pointer;}\n#ar-widget .ar-times{display:flex;justify-content:space-between;font-size:10px;color:#9ca3af;margin-top:3px;}\n#ar-widget .ar-controls{display:flex;align-items:center;gap:7px;flex-wrap:wrap;}\n#ar-widget .ar-controls button{border:1px solid #d1d5db;border-radius:8px;padding:5px 11px;background:#fff;cursor:pointer;font-size:12px;color:#374151;}\n#ar-widget .ar-controls button:hover{background:#f9fafb;}\n#ar-widget .ar-play-btn{border-color:#534AB7!important;color:#534AB7!important;font-weight:600;min-width:86px;text-align:center;}\n#ar-widget .ar-play-btn:hover{background:#EEEDFE!important;}\n#ar-widget .ar-speed-wrap{margin-left:auto;display:flex;align-items:center;gap:5px;}\n#ar-widget .ar-speed-wrap label{font-size:11px;color:#6b7280;}\n#ar-widget #ar-rate{border:1px solid #d1d5db;border-radius:6px;padding:3px 5px;font-size:11px;background:#fff;color:#374151;cursor:pointer;}\n#ar-widget #ar-status{font-size:11px;color:#9ca3af;margin:.65rem 0 0;padding-top:.65rem;border-top:1px solid #f3f4f6;}\n#ar-widget .ar-voice-row{display:flex;align-items:center;gap:6px;margin-top:8px;}\n#ar-widget .ar-voice-row label{font-size:11px;color:#6b7280;flex-shrink:0;}\n#ar-widget #ar-voice{flex:1;min-width:0;border:1px solid #d1d5db;border-radius:6px;padding:4px 6px;font-size:11px;background:#fff;color:#374151;cursor:pointer;}\n]]><\/style>\n<p class=\"wp-block-paragraph\">Staff connecting to resort or convention Wi-Fi are being focused via the community gear managing their connection, permitting attackers to redirect them to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/hackers-fake-microsoft-adfs-login-pages-steal-credentials\/\" data-type=\"post\" data-id=\"125565\">faux Microsoft login pages<\/a> with out sending a phishing e mail or infecting their computer systems.<\/p>\n<p class=\"wp-block-paragraph\">The marketing campaign has operated since at the least June 2026, in accordance with analysis printed by ReliaQuest, which recognized compromised Wi-Fi gateways in a number of US cities, India, and Saudi Arabia, with connections involving workers from finance, authorized, well being care, power, retail, {and professional} companies organizations.<\/p>\n<p class=\"wp-block-paragraph\">For context, a resort visitor can be part of the venue\u2019s real Wi-Fi community and nonetheless be uncovered. As soon as attackers receive administrative entry to its gateway, they will alter the system that directs web visitors for each related visitor.<\/p>\n<h3 id=\"compromised-wi-fi-redirects-microsoft-logins\" class=\"wp-block-heading\"><strong>Compromised Wi-Fi Redirects Microsoft Logins<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">When a tool requests a web site, DNS converts its title into the numerical handle wanted to succeed in it. A compromised gateway can present a false reply, sending the browser to infrastructure operated by the attacker.<\/p>\n<p class=\"wp-block-paragraph\">ReliaQuest noticed Microsoft-themed domains reminiscent of <code>m365-owa.com, owa-ms365.com, ms365-device.com<\/code> and <code>ms365-live.com<\/code>. These weren&#8217;t Microsoft companies, however names designed to resemble official Microsoft 365 and Outlook addresses.<\/p>\n<p class=\"wp-block-paragraph\">In line with ReliaQuest\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality\/\" rel=\"nofollow noopener\" target=\"_blank\">weblog put up<\/a>, vacationers redirected to these pages could possibly be requested to enter their login particulars. In a restricted variety of instances, the attackers additionally abused Microsoft\u2019s device-code authentication course of. A sufferer approving the request might give the attacker legitimate entry tokens, even when multifactor authentication was accomplished on a real Microsoft web page.<\/p>\n<p class=\"wp-block-paragraph\">The researchers consider the gateways could have been compromised via internet-facing administration companies mixed with weak or reused administrator passwords. Nonetheless, restricted entry to the affected gadgets prevented them from confirming the preliminary entry technique.<\/p>\n<p class=\"wp-block-paragraph\">Some affected gadgets additionally tried to make use of Home windows Net Proxy Auto-Discovery, often known as WPAD, to route software visitors via an attacker-controlled proxy. ReliaQuest noticed this exercise in roughly one-third of the examined instances however couldn&#8217;t affirm that it succeeded.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/07\/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"154\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/07\/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts.jpg\" alt=\"\" class=\"wp-image-147892\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/07\/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts.jpg 1000w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/07\/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts-300x46.jpg 300w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/07\/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts-768x118.jpg 768w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/07\/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts-380x59.jpg 380w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/07\/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts-800x123.jpg 800w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\"\/><\/a><figcaption class=\"wp-element-caption\">Assault circulation (By way of ReliaQuest)<\/figcaption><\/figure>\n<\/div>\n<h3 id=\"techniques-resemble-earlier-apt28-campaigns\" class=\"wp-block-heading\"><strong>Strategies Resemble Earlier APT28 Campaigns<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">ReliaQuest discovered similarities between this operation and earlier router assaults related to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/russian-apt28-notdoor-backdoor-microsoft-outlook\/\" data-type=\"post\" data-id=\"134423\">APT28<\/a>, additionally known as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/fancy-bear-hackers-graphite-malware-powerpoint\/\" data-type=\"post\" data-id=\"90262\">Fancy Bear<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/russian-forest-blizzard-hackers-hijack-home-routers\/\" data-type=\"post\" data-id=\"143575\">Forest Blizzard<\/a>. The Russian army intelligence group has beforehand been linked to DNS manipulation used to compromise Microsoft 365 accounts.<\/p>\n<p class=\"wp-block-paragraph\">These similarities embody taking management of community gateways, altering DNS responses and directing Microsoft authentication visitors via an adversary-in-the-middle service. ReliaQuest didn&#8217;t immediately attribute the brand new marketing campaign to APT28 as a result of it discovered no shared infrastructure, reused code or different agency technical connection.<\/p>\n<p class=\"wp-block-paragraph\">Moreover, researchers discovered a number of variations. As an example, the present operation targets resort and convention Wi-Fi gear, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/russia-apt28-windows-vulnerability-gooseegg-tool\/\" data-type=\"post\" data-id=\"115913\">whereas earlier APT28 reporting<\/a> targeted on residence and small-office routers. Its domains and IP addresses additionally differ from infrastructure beforehand related to the Russian group.<\/p>\n<h3 id=\"always-on-vpn-stops-the-wi-fi-redirect\" class=\"wp-block-heading\"><strong>At all times-On VPN Stops the Wi-Fi Redirect<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">ReliaQuest says an always-on, full-tunnel VPN can cease this assault by sending web visitors and DNS requests via the corporate community. The resort gateway can not redirect the worker to a faux login web page as a result of the VPN handles these requests first.<\/p>\n<p class=\"wp-block-paragraph\">This safety must activate as quickly because the system connects. A VPN that workers begin manually could go away a brief interval when the resort community can intrude with visitors, whereas break up tunneling can go away DNS requests outdoors the protected connection.<\/p>\n<p class=\"wp-block-paragraph\">The researchers additionally warn that merely altering the system to Google\u2019s <code>8.8.8.8<\/code> DNS service will not be sufficient. Until the request is encrypted, it nonetheless travels via the compromised gateway, which might intercept it and return a false handle.<\/p>\n<p class=\"wp-block-paragraph\">Nonetheless, workers ought to reject sudden Microsoft login or authorization requests on public Wi-Fi and inform their employer which venue and community they have been utilizing.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="xMmWewK0NbzHku4ZVQm7"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Staff connecting to resort or convention Wi-Fi are being focused via the community gear managing their connection, permitting attackers to redirect them to faux Microsoft login pages with out sending a phishing e mail or infecting their computer systems. The marketing campaign has operated since at the least June 2026, in accordance with analysis printed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17144,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[172,1429,6507,554,1119,4459,618,169],"class_list":["post-17142","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-accounts","tag-compromise","tag-gateways","tag-hackers","tag-hijack","tag-hotel","tag-microsoft","tag-wifi"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17142","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17142"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17142\/revisions"}],"predecessor-version":[{"id":17143,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17142\/revisions\/17143"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17144"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17142"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17142"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17142"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-27 22:02:24 UTC -->