What's Happening?
A cyber espionage campaign attributed to APT28, also known as Fancy Bear, is targeting hotel Wi-Fi routers to steal corporate login credentials. The campaign involves DNS poisoning, redirecting web traffic through attacker-controlled infrastructure without
the need for phishing links or malicious attachments. This attack has been identified in multiple U.S. cities and other countries. The attackers exploit exposed management interfaces and weak admin credentials to gain initial access to the routers. The campaign is ongoing, and cybersecurity firm ReliaQuest has issued recommendations to prevent such attacks.
Why It's Important?
This campaign highlights the vulnerabilities in public Wi-Fi networks, particularly those used by corporate travelers. The ability to harvest corporate credentials without direct interaction with the victim's device poses a significant threat to businesses, potentially leading to unauthorized access to sensitive information. The involvement of APT28, linked to Russian military intelligence, underscores the geopolitical dimensions of cyber espionage. Organizations must strengthen their network security measures to protect against such sophisticated attacks.
What's Next?
Organizations operating captive portal networks, such as hotels and conference centers, need to implement stronger security protocols to prevent DNS poisoning. This includes securing management interfaces and using strong, unique admin credentials. Cybersecurity firms and government agencies may increase efforts to track and mitigate the activities of APT28 and similar groups. Businesses should also educate employees on the risks of using public Wi-Fi networks and encourage the use of VPNs for secure connections.











