Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
A threat actor has been hacking public Wi-Fi gateway appliances at organizations running captive portal networks to compromise the Microsoft 365 accounts of traveling corporate employees, ReliaQuest reports.
As part of the attacks, the hackers modified the DNS configurations of the compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure for credential theft.
Ongoing since at least June 2026, the activity is similar to the previously observed FrostArmada campaign, which was attributed to APT28, also known as Forest Blizzard, and Fancy Bear, a state-sponsored group believed to be linked to Russia’s General Staff Main Intelligence Directorate (GRU).
Using the adversary-in-the-middle (AitM) technique, the hackers can intercept the victims’ traffic and harvest their credentials and other sensitive information.
The newly observed activity, ReliaQuest says, involved hacked Wi-Fi gateways at shared venues such as hotels and conference centers across the US, India, and Saudi Arabia.
The cybersecurity firm...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE