What's Happening?
A cybersecurity firm, ReliaQuest, has identified a new cyber threat involving the hacking of public Wi-Fi gateway appliances at organizations with captive portal networks. This attack targets the Microsoft 365 accounts of traveling corporate employees.
The hackers have been modifying DNS configurations of compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure, facilitating credential theft. This activity, ongoing since at least June 2026, is similar to the FrostArmada campaign, previously attributed to APT28, a group linked to Russia's GRU. The attacks have been observed at shared venues such as hotels and conference centers across the US, India, and Saudi Arabia. The campaign is not sector-specific, affecting industries like financial services, healthcare, and retail.
Why It's Important?
This development underscores the persistent threat of cyber espionage targeting corporate entities, particularly those with employees who travel frequently. The ability to compromise Microsoft 365 accounts poses significant risks, including unauthorized access to sensitive corporate data and potential financial losses. The use of public Wi-Fi networks as an attack vector highlights vulnerabilities in common connectivity solutions used by businesses. Organizations across various sectors, including healthcare and financial services, are at risk, emphasizing the need for robust cybersecurity measures. The attack's similarity to previous state-sponsored campaigns suggests ongoing geopolitical tensions influencing cyber activities.
What's Next?
Organizations operating captive Wi-Fi services, such as airports and conference centers, need to enhance their cybersecurity protocols to mitigate such threats. This includes monitoring DNS configurations and implementing advanced threat detection systems. Businesses should educate employees on safe internet practices, especially when using public Wi-Fi. Cybersecurity firms and government agencies may increase collaboration to identify and neutralize such threats. The evolving tactics of cyber attackers necessitate continuous updates to security strategies to protect against sophisticated espionage activities.











