SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Reading: DNS Poisoning Campaign Makes Hospitality Wi-Fi Spots Inhospitable
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > News > DNS Poisoning Campaign Makes Hospitality Wi-Fi Spots Inhospitable
News

DNS Poisoning Campaign Makes Hospitality Wi-Fi Spots Inhospitable

News Room
Last updated: July 29, 2026 12:17 pm
News Room
Share
9 Min Read
SHARE

In what appears to be a state-sponsored credential theft campaign, a group of network marauders has been targeting Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack corporate travelers’ accounts.

Once the threat actors control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, according to a report by ReliaQuest, a global security operations and threat response automation company.

According to ReliaQuest, the activity has been ongoing since at least June 2026.

The compromised devices investigated by ReliaQuest were appliances primarily used at hotels and other organizations running captive Wi-Fi services, explained the report authored by researchers Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie and Connor Short.

The researchers said, with “low-to-medium confidence,” that the attackers likely gained initial access through exposed management interfaces combined with weak or reused administrative credentials, although limited visibility into the compromised devices prevented them from confirming that assessment.

That methodology would be consistent with the gateway targeting and DNS poisoning patterns documented in recent reporting on an APT28-linked campaign known as “FrostArmada,” the report noted.

FrostArmada, a cyberespionage campaign linked to the Russian threat group Forest Blizzard, also known as APT28 and Fancy Bear, hijacked DNS settings on compromised routers to redirect authentication traffic and steal Microsoft credentials and OAuth tokens. It was disrupted in April 2026 through a joint operation involving law enforcement and private-sector partners.

The report explained that once the attacker compromised the gateway devices, they modified their configurations and used DNS poisoning to redirect regular web traffic, funneling connections for legitimate domains through attacker-controlled infrastructure.

Stealthy Attack

“Hotels and conference centers are not random targets,” observed James Edwards, senior director of engineering at Keeper Security, a password management and online storage company in Chicago.

“These are environments where senior executives, legal teams, financial professionals and other high-value corporate employees routinely connect to shared Wi-Fi without thinking twice about it,” he told TechNewsWorld.

“A single compromised gateway at a major industry conference gives an attacker access to hundreds — or even thousands — of corporate devices from a range of organizations,” he explained. “The infrastructure economics are extraordinary.”

“What makes this campaign particularly dangerous is that it operates entirely below the user’s awareness,” he continued. “When an attacker owns the gateway, they don’t need to touch a single endpoint, send a single phishing email or plant a single piece of malware.”

“DNS poisoning redirects traffic silently,” he added. “The user browses normally, enters credentials normally and has no reason to suspect anything is wrong.”

Concerning Attack Technique

These attacks are becoming increasingly common, noted Denis Calderone, principal and CTO of Suzu Labs, a provider of AI-powered cybersecurity services in Las Vegas.

“This is basically the same playbook as what APT28 did with 18,000 home routers in the FrostArmada campaign back in April,” he told TechNewsWorld. “In this case, the attacker is targeting legitimate hotel Wi-Fi gateways.”

One particularly concerning aspect of the campaign involves device-code authentication abuse, in which the user is redirected to what appears to be a legitimate Microsoft authorization prompt.

“If the user approves it, it actually authorizes a session the attacker initiated,” he said. “Microsoft issues a valid OAuth token to the attacker’s client, and that token is already MFA-satisfied. No credentials stolen. No tokens intercepted. MFA completely bypassed.”

“Device-code authentication was designed for input-constrained devices like smart TVs and conference room displays, but it’s enabled by default in Microsoft’s Entra ID service, and many enterprises have never turned it off because they don’t know it’s there,” he explained.

He recommended disabling the service via Conditional Access for all users except the handful of service accounts or device groups that genuinely need it.

Long-Expected Attack Becomes Reality

“What surprises me most isn’t the technique, it’s the timeline,” observed Larry Pesce, vice president of services at Columbus, Ohio-based Finite State, which automates security compliance and analysis for connected device manufacturers.

“Security researchers have been demonstrating and warning about exactly this class of attack for the better part of a decade,” he told TechNewsWorld. “What’s new here isn’t the method. It’s that we finally have large-scale, in-the-wild evidence that real threat actors are operationalizing it.”

“The gap between ‘we know this is possible’ and ‘we can prove it’s happening’ just closed, and that should worry anyone who travels for work,” he said.

He added that understanding the threat actors in the campaign can be worthwhile.

“If this is APT28 or something in that orbit, the interesting shift is who they went after,” he noted. “Groups like this have historically been surgical, redirecting only traffic that matched specific keywords or targets. What researchers describe here is the opposite: non-selective redirection that scooped up anyone who connected.”

“The takeaway here isn’t ‘I’m not important enough to be a target,'” he warned. “On a shared, compromised network, importance is decided after the fact. You give up the credential first, and someone else decides later how to monetize or weaponize it.”

“That’s exactly why hygiene matters for everyone, not just the executives and the obvious high-risk roles,” he added. “The person who assumes they’re not worth targeting is often the easiest way in.”

Changing Targeting Strategy

Seemant Sehgal, CEO and founder of BreachLock, a penetration testing company in New York City, maintained that the campaign relied less on sophisticated techniques than on weak security practices at the targeted gateways.

“The failure point here is that these gateways were reachable with credentials that could be compromised in the first place, and whatever monitoring existed on them was not watching for configuration changes,” he told TechNewsWorld.

Keeper Security’s Edwards acknowledged that DNS-based attacks are not new but added that they have historically required access to upstream infrastructure or individual device compromise.

“What has changed is the targeting model,” he explained. “Attacking shared network gateways in high-traffic venues turns a single point of compromise into a force multiplier, where one router yields access to hundreds of corporate devices across dozens of organizations simultaneously.”

Weaponizing Trust

“That expansion from home office and small business networks into the hospitality environments that corporate employees move through every day represents a meaningful shift in both who is exposed and how little warning they receive,” he said.

“What this campaign exposes, more than any specific technique, is how thoroughly attackers have learned to weaponize trust,” he argued.

“The hotel network is trusted because the hotel provides it,” he noted. “The Microsoft sign-in prompt is trusted because it looks exactly right. The OAuth authorization is trusted because it is, technically, legitimate.”

“None of those assumptions hold in an environment where the infrastructure itself has been compromised,” he continued. “The real lesson here is not that a new attack technique has emerged, but that the perimeter organizations believed they were operating inside does not exist the moment an employee connects to a network they don’t control.”

“The organizations that come through this kind of campaign intact are the ones that have already stopped extending implicit trust to infrastructure they don’t own,” he added. “That is not a new principle. It is simply one the hospitality sector, and the enterprises whose employees travel through it, can no longer afford to defer.”

According to ReliaQuest, organizations can significantly reduce their exposure by requiring corporate devices to use always-on, full-tunnel VPNs that route DNS requests through trusted corporate infrastructure before they reach hotel or conference-center gateways.

Read the full article here

You Might Also Like

Study Finds Most Restaurants Missing From AI Recommendations

AI’s ‘annual physical’ surfaces one big surprise – GeekWire

General Fusion set to become first publicly traded fusion stock – GeekWire

Expeditors cuts 230 tech jobs in Seattle region, ending decades-long policy against layoffs – GeekWire

Docusign moving downtown Seattle offices, leaving its namesake tower – GeekWire

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

News

Salesforce hires ex-Microsoft exec to lead Agentforce engineering amid string of departures – GeekWire

July 31, 2026
Games

Bulletstorm is the stupidest game ever made, and also one of the cleverest shooters ever

July 31, 2026
News

Which Microsoft businesses are growing and shrinking, according to obscure table in regulatory filing – GeekWire

July 31, 2026
Games

Former WoW designer says Blizzard had no way to measure maximum player DPS while building early raids—so the studio enlisted its strongest sickos to grind target dummies

July 31, 2026
Software

Copilot worm can spread through Microsoft Word docs

July 31, 2026
News

AI, startups, and the best insights and takeaways we heard – GeekWire

July 31, 2026

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?