Cybersecurity firm ReliaQuest has identified a campaign where hackers are altering DNS settings on Wi-Fi devices located in hotels and conference centers. This manipulation redirects users attempting to access Microsoft 365 services to fraudulent login pages controlled by the attackers. The campaign has been active since at least June and has been observed in multiple U.S. cities and international regions like India and Saudi Arabia.
The compromised Wi-Fi gateways serve corporate events, making the campaign a threat to various industries. Organizations in financial services, professional services, legal, healthcare, energy, and retail have been affected. By hijacking Microsoft 365 accounts, attackers could gain access to sensitive business information, communications, and private documents, indicating a broad, non-sector-specific targeting strategy aimed at traveling employees.
The initial access method to the Wi-Fi appliances is currently unknown, but ReliaQuest suggests attackers may exploit weakly protected management interfaces or vulnerabilities. Once administrative access is gained, the threat actor modifies the gateway's DNS settings to redirect legitimate domain requests to attacker-controlled infrastructure. ReliaQuest identified four domains used for these fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.
When DNS settings are altered, users are directed to phishing pages where they might enter their Microsoft 365 credentials. In some instances, a device-code authentication flow is observed, where targets are prompted on a fake Microsoft page. Approving this prompt authorizes a session initiated by the attacker, leading to a legitimate OAuth token being issued to the attacker's client, effectively bypassing multi-factor authentication (MFA) without directly stealing credentials.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft has attributed a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard (APT29), also known as Storm-2945. This campaign, named CaptiveCrunch, uses custom malware families CornFlake and ChocoShell to steal Microsoft 365 accounts and exfiltrate data, impacting users of hotel and conference center Wi-Fi.
Microsoft reports that Russian state-sponsored hackers, identified as Storm-2945 (a sub-cluster of Midnight Blizzard), are compromising hotel Wi-Fi networks globally to steal login credentials and infect devices with espionage malware. The attackers redirect users to fake login pages or fraudulent update screens to deploy malware like CornFlake and ChocoShell, primarily targeting corporate travelers.
Microsoft has attributed a recent credential theft campaign, dubbed CaptiveCrunch, to Storm-2945, a subgroup of the Russian state-sponsored APT Midnight Blizzard. This campaign exploits hacked public Wi-Fi gateway appliances to redirect users and steal Microsoft 365 credentials from traveling employees across various sectors, posing a significant risk to organizational security.
Microsoft reports that a Russian state-sponsored group, Storm-2945 (Midnight Blizzard/APT29), is using hijacked hotel Wi-Fi networks to deliver CornFlake surveillance malware through fake browser updates. This attack method allows the group to capture webcam images, microphone audio, and keystrokes, posing a significant threat to travelers and organizations whose employees use public Wi-Fi.
Threat actors are compromising public Wi-Fi gateway appliances at venues like hotels and conference centers to redirect users to malicious infrastructure and steal Microsoft 365 credentials from traveling corporate employees. This activity, ongoing since at least June 2026, uses DNS poisoning and adversary-in-the-middle techniques, impacting various industries across the US, India, and Saudi Arabia.
Hackers are redirecting users to fake Microsoft 365 login pages by changing DNS settings on Wi-Fi devices in hotels and conference centers. This campaign, ongoing since June, affects organizations across various sectors by potentially compromising sensitive business information.