Security firm ReliaQuest discovered that attackers are hijacking public Wi‑Fi captive‑portal routers to intercept Microsoft 365 logins of traveling employees across the US, India and Saudi Arabia. The campaign mirrors tactics of the Russian‑linked FrostArmada group but uses simpler DNS poisoning.

Key Takeaways

  • Hackers target captive‑portal public Wi‑Fi gateways
  • Compromised DNS settings redirect users to attacker‑controlled servers
  • Multiple industries and regions, including the US, India and Saudi Arabia, are affected

Historical Background

The current campaign draws heavily from the previously observed FrostArmada (APT28/Forest Blizzard) operations, a state‑sponsored group believed to be linked to Russia’s GRU. Between 2022‑2024, FrostArmada exploited public Wi‑Fi infrastructure with sophisticated DNS spoofing and custom command‑and‑control servers.

ReliaQuest identified four attacker‑registered domains used to deliver Microsoft‑impersonation lures. Unlike the earlier campaign, the new attacks rely on broad DNS poisoning to funnel all traffic, suggesting a less meticulous actor but still a potent threat.

Why This Matters

BozokMedia analysis shows that compromising captive‑portal Wi‑Fi devices gives attackers a “golden ticket” to corporate identities, especially for traveling staff who rely on hotel or conference‑center networks. The low‑cost, high‑impact nature of DNS‑based redirection means even midsize firms with limited security budgets are vulnerable.

“The reuse of APT28 tradecraft indicates a low‑cost, high‑impact threat that many enterprises underestimate,” said Dr. Lena Ortiz, cyber‑risk analyst.
Did You Know?: Some compromised routers stay active for months because administrators often overlook subtle DNS changes.

Frequently Asked Questions

Q1: How can organizations secure captive‑portal Wi‑Fi?
A: Deploy multi‑factor authentication, enable DNSSEC, and regularly patch router firmware.

Q2: What are the signs of DNS poisoning?
A: Unexpected redirections, SSL certificate warnings, and anomalous domain query traffic.