Close Menu
Get on News
  • U.S.
  • World
  • Politics
  • Business
  • Finance
  • Lifestyle
  • Sports
  • More Articles
Trending
WATCH: Battleground Democrat called Iowa a ‘backwater’ over transgender athletes ban

WATCH: Battleground Democrat called Iowa a ‘backwater’ over transgender athletes ban

Lost sermons from one of Christianity’s greatest saints discovered after 1,600 years

Lost sermons from one of Christianity’s greatest saints discovered after 1,600 years

Dr. Anthony Fauci pleads the Fifth Amendment in Senate hearing bombshell

Dr. Anthony Fauci pleads the Fifth Amendment in Senate hearing bombshell

Facebook X (Twitter) Instagram
Get on News
  • U.S.
  • World
  • Politics
  • Business
  • Finance
  • Lifestyle
  • Sports
  • More Articles
Facebook X (Twitter) Instagram
Subscribe
Trending Topics:
  • US Election
  • Donald Trump
  • Kamala Harris
  • Entertainment
  • Health
  • Technology
  • Travel
  • Ukraine War
  • Israel War
Get on News
  • U.S.
  • World
  • Politics
  • Business
  • Finance
  • Lifestyle
  • Sports
  • More Articles
Tech

DNS Poisoning Campaign Targets Hospitality Wi-Fi

News RoomBy News RoomJuly 29, 2026No Comments7 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
DNS Poisoning Campaign Targets Hospitality Wi-Fi
Share
Facebook Twitter LinkedIn Pinterest Email

In what appears to be a state-sponsored credential theft campaign, a group of network marauders has been targeting Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack corporate travelers’ accounts.

Once the threat actors control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, according to a report by ReliaQuest, a global security operations and threat response automation company.

According to ReliaQuest, the activity has been ongoing since at least June 2026.

The compromised devices investigated by ReliaQuest were appliances primarily used at hotels and other organizations running captive Wi-Fi services, explained the report authored by researchers Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie and Connor Short.

The researchers said, with “low-to-medium confidence,” that the attackers likely gained initial access through exposed management interfaces combined with weak or reused administrative credentials, although limited visibility into the compromised devices prevented them from confirming that assessment.

That methodology would be consistent with the gateway targeting and DNS poisoning patterns documented in recent reporting on an APT28-linked campaign known as “FrostArmada,” the report noted.

FrostArmada, a cyberespionage campaign linked to the Russian threat group Forest Blizzard, also known as APT28 and Fancy Bear, hijacked DNS settings on compromised routers to redirect authentication traffic and steal Microsoft credentials and OAuth tokens. It was disrupted in April 2026 through a joint operation involving law enforcement and private-sector partners.

The report explained that once the attacker compromised the gateway devices, they modified their configurations and used DNS poisoning to redirect regular web traffic, funneling connections for legitimate domains through attacker-controlled infrastructure.

Stealthy Attack

“Hotels and conference centers are not random targets,” observed James Edwards, senior director of engineering at Keeper Security, a password management and online storage company in Chicago.

“These are environments where senior executives, legal teams, financial professionals and other high-value corporate employees routinely connect to shared Wi-Fi without thinking twice about it,” he told TechNewsWorld.

“A single compromised gateway at a major industry conference gives an attacker access to hundreds — or even thousands — of corporate devices from a range of organizations,” he explained. “The infrastructure economics are extraordinary.”

“What makes this campaign particularly dangerous is that it operates entirely below the user’s awareness,” he continued. “When an attacker owns the gateway, they don’t need to touch a single endpoint, send a single phishing email or plant a single piece of malware.”

“DNS poisoning redirects traffic silently,” he added. “The user browses normally, enters credentials normally and has no reason to suspect anything is wrong.”

Concerning Attack Technique

These attacks are becoming increasingly common, noted Denis Calderone, principal and CTO of Suzu Labs, a provider of AI-powered cybersecurity services in Las Vegas.

“This is basically the same playbook as what APT28 did with 18,000 home routers in the FrostArmada campaign back in April,” he told TechNewsWorld. “In this case, the attacker is targeting legitimate hotel Wi-Fi gateways.”

One particularly concerning aspect of the campaign involves device-code authentication abuse, in which the user is redirected to what appears to be a legitimate Microsoft authorization prompt.

“If the user approves it, it actually authorizes a session the attacker initiated,” he said. “Microsoft issues a valid OAuth token to the attacker’s client, and that token is already MFA-satisfied. No credentials stolen. No tokens intercepted. MFA completely bypassed.”

“Device-code authentication was designed for input-constrained devices like smart TVs and conference room displays, but it’s enabled by default in Microsoft’s Entra ID service, and many enterprises have never turned it off because they don’t know it’s there,” he explained.

He recommended disabling the service via Conditional Access for all users except the handful of service accounts or device groups that genuinely need it.

Long-Expected Attack Becomes Reality

“What surprises me most isn’t the technique, it’s the timeline,” observed Larry Pesce, vice president of services at Columbus, Ohio-based Finite State, which automates security compliance and analysis for connected device manufacturers.

“Security researchers have been demonstrating and warning about exactly this class of attack for the better part of a decade,” he told TechNewsWorld. “What’s new here isn’t the method. It’s that we finally have large-scale, in-the-wild evidence that real threat actors are operationalizing it.”

“The gap between ‘we know this is possible’ and ‘we can prove it’s happening’ just closed, and that should worry anyone who travels for work,” he said.

He added that understanding the threat actors in the campaign can be worthwhile.

“If this is APT28 or something in that orbit, the interesting shift is who they went after,” he noted. “Groups like this have historically been surgical, redirecting only traffic that matched specific keywords or targets. What researchers describe here is the opposite: non-selective redirection that scooped up anyone who connected.”

“The takeaway here isn’t ‘I’m not important enough to be a target,'” he warned. “On a shared, compromised network, importance is decided after the fact. You give up the credential first, and someone else decides later how to monetize or weaponize it.”

“That’s exactly why hygiene matters for everyone, not just the executives and the obvious high-risk roles,” he added. “The person who assumes they’re not worth targeting is often the easiest way in.”

Changing Targeting Strategy

Seemant Sehgal, CEO and founder of BreachLock, a penetration testing company in New York City, maintained that the campaign relied less on sophisticated techniques than on weak security practices at the targeted gateways.

“The failure point here is that these gateways were reachable with credentials that could be compromised in the first place, and whatever monitoring existed on them was not watching for configuration changes,” he told TechNewsWorld.

Keeper Security’s Edwards acknowledged that DNS-based attacks are not new but added that they have historically required access to upstream infrastructure or individual device compromise.

“What has changed is the targeting model,” he explained. “Attacking shared network gateways in high-traffic venues turns a single point of compromise into a force multiplier, where one router yields access to hundreds of corporate devices across dozens of organizations simultaneously.”

Weaponizing Trust

“That expansion from home office and small business networks into the hospitality environments that corporate employees move through every day represents a meaningful shift in both who is exposed and how little warning they receive,” he said.

“What this campaign exposes, more than any specific technique, is how thoroughly attackers have learned to weaponize trust,” he argued.

“The hotel network is trusted because the hotel provides it,” he noted. “The Microsoft sign-in prompt is trusted because it looks exactly right. The OAuth authorization is trusted because it is, technically, legitimate.”

“None of those assumptions hold in an environment where the infrastructure itself has been compromised,” he continued. “The real lesson here is not that a new attack technique has emerged, but that the perimeter organizations believed they were operating inside does not exist the moment an employee connects to a network they don’t control.”

“The organizations that come through this kind of campaign intact are the ones that have already stopped extending implicit trust to infrastructure they don’t own,” he added. “That is not a new principle. It is simply one the hospitality sector, and the enterprises whose employees travel through it, can no longer afford to defer.”

According to ReliaQuest, organizations can significantly reduce their exposure by requiring corporate devices to use always-on, full-tunnel VPNs that route DNS requests through trusted corporate infrastructure before they reach hotel or conference-center gateways.

Read the full article here

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related News

Falling Token Prices Fail To Slow Enterprise AI Spending

Falling Token Prices Fail To Slow Enterprise AI Spending

July 28, 2026
Cyberattacks on Local Governments Are Increasing

Cyberattacks on Local Governments Are Increasing

July 27, 2026
Samsung Unveils Its Finest Foldable Lineup. It’s Your Move, Apple

Samsung Unveils Its Finest Foldable Lineup. It’s Your Move, Apple

July 24, 2026
Leave A Reply Cancel Reply

Demo
Latest News
WATCH: Battleground Democrat called Iowa a ‘backwater’ over transgender athletes ban

WATCH: Battleground Democrat called Iowa a ‘backwater’ over transgender athletes ban

Lost sermons from one of Christianity’s greatest saints discovered after 1,600 years

Lost sermons from one of Christianity’s greatest saints discovered after 1,600 years

Dr. Anthony Fauci pleads the Fifth Amendment in Senate hearing bombshell

Dr. Anthony Fauci pleads the Fifth Amendment in Senate hearing bombshell

DNS Poisoning Campaign Targets Hospitality Wi-Fi

DNS Poisoning Campaign Targets Hospitality Wi-Fi

Trending
WATCH: Battleground Democrat called Iowa a ‘backwater’ over transgender athletes ban

WATCH: Battleground Democrat called Iowa a ‘backwater’ over transgender athletes ban

July 29, 2026
Lost sermons from one of Christianity’s greatest saints discovered after 1,600 years

Lost sermons from one of Christianity’s greatest saints discovered after 1,600 years

July 29, 2026
Dr. Anthony Fauci pleads the Fifth Amendment in Senate hearing bombshell

Dr. Anthony Fauci pleads the Fifth Amendment in Senate hearing bombshell

July 29, 2026

Subscribe to News

Get the latest news and updates directly to your inbox.

Advertisement
Demo
Facebook X (Twitter) Pinterest TikTok Instagram
2026 © Prices.com LLC. All Rights Reserved.
  • Privacy Policy
  • Terms
  • For Advertisers
  • Contact

Type above and press Enter to search. Press Esc to cancel.