Threat actors are compromising public Wi-Fi gateways at hotels and conference centers to silently hijack Microsoft 365 accounts by redirecting user traffic through malicious DNS poisoning attacks.
Key Points
- ReliaQuest researchers identified attackers exploiting weak gateway credentials to intercept traffic without needing to compromise individual user devices.
- The campaign targets users across various sectors, including finance, legal, and healthcare, with incidents reported in the United States, India, and Saudi Arabia.
- Attackers use fraudulent domains like m365-owa[.]com to impersonate Microsoft login pages and steal credentials from unsuspecting travelers.
- Standard security measures like using public DNS providers or DNSSEC are insufficient because they do not encrypt traffic or prevent gateway-level interception.
- Experts recommend using full-tunnel VPNs, disabling automatic proxy discovery, and enforcing strict conditional access policies to mitigate these network-level risks.