Threat actors are compromising hotel and conference-center Wi‑Fi gateways to steal Microsoft 365 accounts from traveling employees without sending phishing emails or infecting endpoints.
The campaign uses DNS poisoning and, in some cases, Microsoft device-code flow abuse to redirect users to attacker-controlled infrastructure.
The activity has reportedly been active since at least June 2026. It affects shared Wi‑Fi environments in multiple U.S. cities, India, and Saudi Arabia.
Financial services, legal, healthcare, energy, retail, and professional-services organizations have all had devices connect through affected gateways, showing that the campaign targets travelers rather than a single industry.
Hotel Wi-Fi Hijacks Microsoft 365 Accounts
The targeted devices are captive-portal appliances that control guest access at hotels, conference centers, airports, coworking spaces, and similar venues.
Once attackers obtain administrative access, potentially through exposed management services and weak or reused credentials, they can alter DNS settings for every client on the network.
DNS converts domain names into IP addresses.
By poisoning DNS responses at the gateway, attackers can answer a request for a legitimate Microsoft sign-in domain with an attacker-controlled IP address, silently steering the victim toward a spoofed Microsoft 365 page.
DNS spoofing is specifically designed to redirect users to malicious sites under attacker control.
ReliaQuest-linked reporting identified domains including m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com in the operation.
The infrastructure was associated with IP addresses 31.57.243[.]154, 104.194.159[.]150, and DNS-poisoning response address 38.146.28[.]75.

This method is especially dangerous because no malicious email, attachment, or endpoint exploit is required. A single compromised gateway can expose every guest device that accepts its DHCP-provided network configuration.
The operation shares tradecraft with prior router-focused activity attributed to APT28, also tracked as Fancy Bear and Forest Blizzard.
The overlap includes compromised network devices, malicious DNS configuration changes, adversary-in-the-middle techniques, and Microsoft 365 credential or token theft; however, the reported activity lacks direct technical evidence required to attribute it to APT28.
Attackers also attempted Web Proxy Auto-Discovery Protocol abuse, or WPAD, against some Windows and macOS systems.
WPAD can automatically obtain proxy settings after a device joins a network; a hostile gateway can direct the device to a malicious proxy auto-configuration file and potentially route application traffic through attacker infrastructure, ReliaQuest said.
Indicators of Compromise
| Type | Indicator | Description |
|---|---|---|
| IP address | 38.146.28[.]75 | DNS poisoning response IP address |
| IP address | 31.57.243[.]154 | Hosts m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com |
| IP address | 104.194.159[.]150 | IP address of ms365-live[.]com |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.
The post Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing appeared first on Cyber Security News.
