Bottom line: APT28 manipulates hotel WLANs through DNS redirection and device code authentication to steal OAuth tokens and bypass MFA—VPN tunneling and encrypted DNS are required.
Security researchers at ReliaQuest have documented an ongoing attack campaign since June 2024 in which attackers manipulate DNS settings in hotel and conference centre WLANs to redirect business travelers to fake Microsoft 365 login pages. The campaign, attributed to the APT28 group, targets organizations across sectors including finance, legal services, healthcare, and retail.
Attackers compromise WLAN gateways in hotels and conference centres at locations across multiple US cities as well as in India and Saudi Arabia. After gaining administrative access, they modify the DNS configuration of the devices so that requests to legitimate Microsoft services are redirected to attacker-controlled domains such as m365-owa[.]com or ms365-live[.]com.
On the fake login pages, the device code authentication method is abused: the user is prompted to perform an alleged confirmation. In the background, however, this action authorizes a session initiated by the attacker, issuing a valid OAuth token to the attacker. In this way, the session can be taken over without intercepting passwords or bypassing multi-factor authentication (MFA)—MFA is effectively neutralized by the legitimate token. In approximately one-third of the cases examined, attackers also attempted to exploit the Web Proxy Auto-Discovery Protocol (WPAD).
ReliaQuest attributes the attack methods to the group known as APT28, Fancy Bear, or Forest Blizzard, which has previously appeared under the name FrostArmada using similar techniques. The observed attacks do not target specific industries but are deliberately focused on business travelers from various sectors connecting to hotel WLANs.
To protect against this, ReliaQuest recommends continuous use of VPN connections with full tunneling and encrypted DNS in strict mode. Using public DNS servers such as 8.8.8.8 offers no protection, as the compromised gateway intercepts unencrypted requests before they reach the resolver. Additionally, the WPAD protocol should be disabled. In Microsoft Entra ID, the device code authentication method can be turned off if it is not strictly required for business processes.
Source: www.it-daily.net · Published 27 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.