Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Accounts
Compromised hotel and conference Wi-Fi gateways are redirecting travelers to fake Microsoft 365 login pages designed to steal credentials and hijack accounts, according to report by ReliaQuest.
The campaign has operated since at least June and has affected gateways in several U.S. cities, India, Saudi Arabia, and other regions.
Hackers Change Wi-Fi Gateway DNS Settings
The attackers gain administrative access to Wi-Fi appliances used by hotels, conference centers, and similar venues. They then alter the gateways’ Domain Name System settings.
DNS normally translates website addresses into the IP addresses needed to reach online services. By controlling these settings, attackers can redirect users away from legitimate Microsoft pages and send them to phishing websites instead.
Researchers have not determined how the attackers initially compromise the gateways. Possible methods include exposed management interfaces, weak administrator credentials, or unpatched security vulnerabilities.
Once attackers gain administrator access, they can change the DNS configuration for every user connected to the affected network.
Travelers Redirected to Microsoft 365 Phishing Pages
Traveling employees who connect to compromised Wi-Fi networks may encounter fake Microsoft 365 login pages while attempting to access legitimate services.
The attackers have used domains including:
- m365-owa[.]com
- owa-ms365[.]com
- ms365-device[.]com
- ms365-live[.]com
These pages imitate Microsoft authentication portals and prompt victims to enter their account credentials.
A compromised Microsoft 365 account could expose corporate emails, documents, SharePoint data, internal conversations, and other sensitive business information.
The campaign affects employees across multiple industries, making hotel and conference Wi-Fi especially risky for organizations with frequent business travelers.
Device Code Authentication Can Bypass MFA
Some attacks use fake Microsoft prompts to abuse device-code authentication instead of directly collecting passwords.
Device-code authentication allows users to authorize devices that may not support standard login methods. The legitimate Microsoft process displays a code that the user enters on another device to approve the session.
In this campaign, the attacker starts the authentication session and tricks the victim into approving it.
Microsoft then issues a legitimate OAuth token to the attacker-controlled client. The attacker can use that token to access the victim’s account.
Because the victim approves a legitimate Microsoft authentication request, the technique can bypass multi-factor authentication without directly stealing credentials, session cookies, or access tokens.
Microsoft 365 customers have faced similar identity-focused attacks. The ARToken phishing platform targeted Microsoft 365 tokens, while another campaign targeted Microsoft 365 users through an Entra passkey voice phishing attack.
The Helix threat group has also targeted Microsoft 365 accounts in SharePoint data-theft attacks.
Attackers Also Attempted WPAD Abuse
Attackers attempted to exploit Web Proxy Auto-Discovery in roughly one-third of the investigated cases.
WPAD allows Windows systems and browsers to automatically locate proxy configuration files on a network. A malicious configuration file could direct web traffic through attacker-controlled proxy servers.
This could give attackers additional control over browser and system traffic from connected devices.
Researchers found evidence of attempted WPAD abuse but could not confirm whether the attackers successfully routed victim traffic through malicious proxies.
How Organizations Can Reduce the Risk
Employees should use an always-on, full-tunnel virtual private network when connecting to hotel, airport, conference, or other public Wi-Fi networks.
Organizations should also enable encrypted DNS in strict mode to prevent devices from relying on DNS servers supplied by an untrusted network.
Administrators should disable WPAD where it is not required and review authentication, DNS, proxy, and network logs for suspicious activity.
Companies that do not require Microsoft Entra device-code authentication should disable it to reduce the risk of attackers abusing the feature.
Security teams should also investigate unexpected OAuth authorizations, unusual login locations, unfamiliar devices, and account activity occurring shortly after employees connect to public Wi-Fi.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages