Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

A Russian state-sponsored APT is behind a recent credential theft campaign mounted via hacked public Wi-Fi gateway appliances at organizations running captive portal networks, Microsoft reports.

The campaign was flagged roughly a week ago by ReliaQuest, which noticed that hackers had modified the DNS configurations of compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure.

The attackers were using the adversary-in-the-middle (AitM) technique to intercept the Microsoft 365 credentials of traveling employees within the financial services, professional services, legal, healthcare, energy, and retail sectors.

ReliaQuest pointed out that the campaign shared similarities with FrostArmada, an espionage operation mounted by Russia-linked APT28 (also known as Forest Blizzard and Fancy Bear), but did not make a clear attribution.

Now Microsoft says that Storm-2945, a subgroup of Midnight Blizzard (also tracked as APT29, Cozy Bear, the Dukes, and Yttrium), a threat actor believed to be sponsored by the Russian...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE