What's Happening?
A cybersecurity threat has emerged involving the hacking of public Wi-Fi gateway appliances at organizations with captive portal networks. According to ReliaQuest, the attackers have been compromising Microsoft 365 accounts of corporate employees by altering
DNS configurations of small office/home office routers. This activity, ongoing since June 2026, resembles the FrostArmada campaign linked to APT28, a group associated with Russia's GRU. The attacks target shared venues like hotels and conference centers, redirecting users to attacker-controlled infrastructure to steal credentials. The campaign affects various industries, including financial services, healthcare, and retail, indicating a broad targeting of traveling employees.
Why It's Important?
This cybersecurity threat highlights the vulnerabilities in public Wi-Fi networks, which are commonly used by corporate employees while traveling. The ability of attackers to intercept and harvest sensitive information poses significant risks to businesses, potentially leading to data breaches and financial losses. The campaign's broad targeting across multiple industries underscores the need for enhanced security measures in public Wi-Fi networks. Organizations must be vigilant in protecting their networks and educating employees about the risks of using unsecured connections.
What's Next?
Organizations using captive Wi-Fi services are advised to review and strengthen their security protocols to prevent similar attacks. This includes monitoring DNS configurations and implementing robust authentication measures. As the threat landscape evolves, businesses may need to invest in advanced cybersecurity solutions to protect their networks and data. The ongoing nature of these attacks suggests that further incidents could occur, prompting a need for continuous vigilance and adaptation to emerging threats.











