Lisbon · Tuesday, 28 Jul 2026 NB Edition · Nº 091
← Back to news
Cibersegurança · Wi-Fi NB-L091

Whoever runs the hotel Wi-Fi decides which pages you open

A ReliaQuest report describes a campaign running since June: Wi-Fi gateways in hotels and conference centres compromised to steer guests to pages impersonating Microsoft and take over their work accounts, with no phishing email involved.

Whoever runs the hotel Wi-Fi decides which pages you open
FIG. NB-L091 · Cibersegurança · Wi-Fi

On July 23, 2026, ReliaQuest published a report describing a campaign that has been running since at least June. Attackers took control of the equipment that hands out Wi-Fi in hotels and conference centres and used that position to steer guests towards pages impersonating Microsoft. The targets are the Microsoft 365 accounts of people working away from the office. There was no phishing email, no malicious attachment, and no contact with the victim's computer at all.

The compromised devices the firm investigated are captive portals, the appliance behind the welcome page a network shows before it lets you browse. They were found in several US cities, in India and in Saudi Arabia, mostly in hospitality. Traffic passing through them came from organisations in financial services, professional services, legal, health care, energy and retail, which the authors read as a campaign chasing travelling employees rather than any particular sector.

What DNS poisoning means

When a device joins a network, it asks that network where each site it wants to visit actually lives. That translation, from a name such as login.microsoftonline.com into a numeric address, is DNS, and the answer normally comes from the very box handing out the Wi-Fi. That is where the weakness sits. With administrative access to the captive portal, the attacker gets to answer whatever suits him for every device that connects that day. This is DNS poisoning, and it requires touching nobody's phone or laptop. In the cases investigated, the forged responses sent clients to hosts serving what ReliaQuest assesses with medium confidence to be Microsoft-impersonating pages.

ReliaQuest identified four attacker-registered domains, all impersonating Microsoft services, and assesses with high confidence that they belong to the same operator, based on shared registration details and on their appearing within a single browsing session seconds apart. On how the devices were breached in the first place, the firm is more careful. It assesses with low-to-medium confidence that the attackers exploited internet-facing management interfaces such as SSH, SNMP and web administration consoles, combined with weak or reused administrative passwords. Visibility into the individual devices was not enough to confirm the hypothesis.

Two extra moves

In roughly one third of observed cases, the attackers also tried to abuse WPAD, a Windows feature that goes looking for proxy settings on its own when a device joins a network. Had it worked, it would have routed most application traffic through the attacker's proxy, not just authentication traffic. ReliaQuest could not confirm success in these cases and describes the attempt as opportunistic.

In a limited number of cases something more serious showed up, abuse of Microsoft's device-code authentication flow. The user is taken to what looks like a legitimate authorisation prompt and, by approving it, authorises a session the attacker started. Microsoft then issues valid access tokens, the temporary keys that keep a session open, to the wrong side, with multi-factor authentication already satisfied and without anyone typing a password into a fake page.

What stops it, and what does not

Pointing your computer at a public DNS server such as Google's 8.8.8.8 does not help. The request still leaves the device unencrypted, and the network box can read it, forge it and redirect it. Turning on encrypted DNS is not enough either if it runs in the mode most tools ship with, opportunistic, because that allows a fallback to plaintext whenever encrypted resolution fails, and the fallback is exactly what the attacker redirects.

According to the report, only two configurations stop the attack at source: an always-on VPN in full-tunnel mode, which routes all traffic and DNS through the corporate network before it ever reaches the hotel gateway, or encrypted DNS in strict mode, with no plaintext fallback. The remaining recommendations are to disable WPAD on Windows where it is not needed, block the device-code flow in Microsoft Entra ID, audit proxy authentication logs for sign-ins coming from unknown hosts, and check the address and certificate of any page before typing a password into it.

A resemblance, not an accusation

The tradecraft resembles that of APT28, also known as Fancy Bear and Forest Blizzard, a group attributed to Russian military intelligence and linked to FrostArmada, a campaign taken down by an international operation in April 2026. FrostArmada altered DNS settings on home and small-office routers, mostly TP-Link and MikroTik, to the same end, and at its peak in December 2025 more than 18,000 unique IP addresses across at least 120 countries were talking to the group's infrastructure, according to reporting at the time of the takedown. ReliaQuest stresses that it does not attribute this campaign to APT28, because the assessment rests on overlapping tactics rather than direct technical evidence such as shared infrastructure or code reuse. The differences are real. Hotel captive portals do not appear in what was documented about FrostArmada, the domains and addresses do not match the group's earlier activity, and here every DNS request was redirected instead of filtered by keyword, which the authors read as a possible mark of a less careful operator.

The source of the document is worth framing. The report comes from a company that sells detection and response, and one of its closing sections describes its own tooling. Against that, the technical indicators were published in full, including the four domains, the addresses hosting them and the email used to register them, which lets any team verify them independently.

On the day of publication, ReliaQuest was still seeing an operator administration panel on one of those domains, with features to swap pages, track visitors and filter who gets served what. It concludes the campaign may still be live. For anyone joining a hotel network, the practical reading is an uncomfortable one: the decision about where the traffic goes does not sit with the person connecting.

Sources: ReliaQuest Threat Research, SecurityWeek, CyberInsider, The Hacker News.

#StaySafe
🙏🖖

Keep reading

More stories

See all →
Summer is high season for scammers too
Cibersegurança · Burlas

Summer is high season for scammers too

Holiday homes that don't exist, bookings that need 'confirming', houses flagged empty on social media: summer concentrat...

5 MIN · 10 Jul 2026 · NB-L073
No one broke into Microsoft 365: they hid an order in a link and the AI obeyed
Cibersegurança · IA

No one broke into Microsoft 365: they hid an order in a link and the AI obeyed

A single click on a microsoft.com link was enough for Microsoft 365 AI to hand over emails, files and multi-factor codes...

4 MIN · 16 Jun 2026 · NB-L038
India ordered the deletion of the code that lets your phone talk when the internet is cut
Cibersegurança · Código aberto

India ordered the deletion of the code that lets your phone talk when the internet is cut

At 11:16 pm on 23 July, India gave GitHub three hours to delete the code of an app that works with no internet. The orde...

5 MIN · 26 Jul 2026 · NB-L090
Weekly · No spam

The Boletim

A weekly summary of the cybersecurity, AI and technology stories that matter — written to be read in five minutes.

Unsubscribe with one click, any week.
BRI assistant

Quer saber sobre um projeto, um serviço ou uma notícia recente? Pergunte. Conheço todo o conteúdo deste site.