Skip to content

Attackers Compromise Hotel Wi-Fi Gateways for Microsoft 365 Attacks

The point: Attackers compromise Wi-Fi gateways on travel networks to steal Microsoft 365 accounts via DNS redirection — an attack surface below endpoint visibility with potential for account cascades in enterprise networks.

Since at least June, threat actors have been hijacking Wi-Fi gateways and portal appliances in hotels and conference centers to hijack Microsoft 365 accounts of traveling corporate employees. The risk lies at the network level below the typical trust assumptions of endpoints and is existential for individual accounts.

The ReliaQuest Threat Research Team documents a campaign in which attackers penetrate Wi-Fi gateways through weak or reused admin credentials and exposed interfaces such as SSH, SNMP, and web consoles. With admin access to the gateway, they can manipulate DNS queries and redirect user traffic to their own infrastructure. Affected devices are redirected to phishing domains such as m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com, where Microsoft 365 login credentials are harvested — without ever touching the endpoint device itself.

Share on: