A threat actor has been compromising public Wi-Fi gateway appliances at venues like hotels and conference centers across the US, India, and Saudi Arabia to hijack DNS settings and redirect users to attacker-controlled sites, harvesting Microsoft 365 credentials of traveling corporate employees. This ongoing campaign since June 2026 resembles tactics used by the Russian-linked APT28 group but shows differences in infrastructure and targeting, suggesting a possible reuse of known tradecraft by a different actor. Organizations providing captive portal Wi-Fi services face heightened risks as attackers employ adversary-in-the-middle techniques to intercept sensitive information from multiple industries.
https://www.securityweek.com/hacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials/

