DNS Poisoning on Hotel Wi-Fi Used to Steal Microsoft 365 Corporate Credentials
Cybersecurity researchers have identified a high-severity attack campaign in which threat actors compromise Wi-Fi gateway management interfaces at hotels and conference centers to manipulate DNS responses. Victims connecting to these networks are silently redirected to convincing fake Microsoft 365 sign-in pages without any phishing email or malicious link involved. The attackers also exploit the WPAD protocol to route device traffic through a malicious proxy, enabling them to harvest OAuth tokens via Microsoft Entra ID's device-code authentication flow. Because no malware is planted on the victim's device and the fake pages closely mimic legitimate Microsoft interfaces, users are unlikely to detect the compromise. Mitigations include enforcing always-on VPNs, disabling WPAD, blocking device-code flows in Conditional Access policies, and requiring phishing-resistant MFA with device compliance checks.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in