One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers

One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers










One compromised hotel Wi-Fi gateway can silently redirect every guest to attacker controlled servers, putting corporate accounts at risk even when users think they are browsing safely.

The campaign starts with a simple idea that many travelers overlook. When you connect to hotel or conference Wi-Fi, you trust that gateway to handle your traffic honestly.

In this case, attackers abuse that trust to quietly steer every guest’s web requests through infrastructure they control, with no malware alert or phishing email required.

Threat actors are poisoning DNS responses at captive portal appliances in hotels, conference centers, and other shared venues to harvest Microsoft 365 credentials from traveling employees.

Activity has been observed across multiple cities in the United States, India, and Saudi Arabia, affecting guests from sectors like finance, legal, health care, energy, and retail.

Reliaquest said in a report shared with Cyber Security News (CSN) that they identified this campaign as part of a broader expansion of DNS poisoning techniques from small office routers to large hospitality networks.

Reliaquest’s Threat Research team notes that the tradecraft looks similar to techniques linked to APT28, also known as Fancy Bear and Forest Blizzard, which previously targeted SOHO routers by altering DNS settings.

In both cases, attackers change how DNS works at the gateway so that any domain a user tries to visit can be silently answered with an attacker owned IP address and lookalike Microsoft pages.

The behavior closely resembles several patterns covered in dangerous DNS attacks types and prevention measures and shows how cache poisoning remains a powerful tool in modern attacks.

The impact is wide and subtle. A single compromised captive portal appliance sits at the edge of the network for every guest device, which means one successful intrusion can redirect traffic from every laptop and phone that signs in that day.

For organizations relying on public Wi-Fi, this risk looks a lot like classic DNS hijacking, but scaled through hotel infrastructure instead of home routers, underscoring advice found in online safety basics for you and your family about avoiding sensitive activity on shared networks.

One Compromised Wi-Fi Gateway

The core of the attack is gateway compromise. Reliaquest assesses that threat actors likely exploit exposed management interfaces like internet facing SSH, SNMP, or web admin consoles using weak or reused credentials to gain administrative access to captive portal appliances.

Once inside, they modify DNS settings so that every client on the network receives forged answers that point to attacker controlled servers instead of legitimate Microsoft domains.

DNS poisoning attack flow (Source - Reliaquest)
DNS poisoning attack flow (Source – Reliaquest)

That single change turns the gateway into an adversary in the middle for all guests. Every employee who connects to the hotel network has their traffic routed through attacker infrastructure without any direct contact with their device.

There is no phishing link to click and no malicious attachment; the user simply opens a browser and sees a Microsoft sign in page convincing enough to trust.

Reliaquest observed attacker registered domains such as m365-owa.com, owa-ms365.com, ms365-device.com, and ms365-live.com being served from IP addresses 31.57.243.154 and 104.194.159.150.

These domains impersonate Microsoft services and are used to capture credentials or abuse Microsoft’s device code flow, giving attackers OAuth tokens and multi factor satisfied access to Microsoft 365 without directly stealing passwords.

That flow abuse matches patterns, where legitimate login prompts are turned into silent session hijacks.

In roughly one third of observed cases, the attacker also tried to abuse Web Proxy Auto Discovery so that Windows devices fetch a malicious proxy auto configuration file and silently route more traffic through attacker proxies.

For victims, this often looks like normal HTTPS traffic in logs, which makes it easy for organizations to miss if they are not routinely reviewing proxy authentication records for unfamiliar hosts and IPs.

Defending against hotel Wi-Fi DNS poisoning

Reliaquest’s report stresses that always on VPN with full tunnel configuration is one of the most effective ways to stop this attack, because it ensures all DNS requests go through trusted corporate resolvers before they ever reach the hotel gateway.

This defense aligns with guidance that public Wi-Fi should be treated as untrusted and paired with VPN. Organizations should also audit split tunneling exceptions that might allow DNS or authentication traffic to bypass the VPN and enforce policies that block internet access until the tunnel is active.

Encrypted DNS in strict mode is the second key control. Reliaquest notes that many endpoint DNS encryption tools default to opportunistic mode, which allows plaintext fallback when encrypted resolution fails.

That fallback becomes the weak point the gateway can redirect, so switching to strict DNS over HTTPS or DNS over TLS removes the attacker’s chance to forge responses.

Beyond network controls, Reliaquest recommends disabling WPAD where it is not required and restricting proxy auto configuration file retrieval to approved internal hosts if automatic proxy discovery must remain enabled.

They also advise organizations to train employees to verify URLs and certificates before entering credentials on any page, especially when using hotel or conference Wi-Fi.

Finally, organizations can close off the device code path by blocking the device code authentication flow at the identity provider using Conditional Access policies in Microsoft Entra ID.

Reliaquest points out that this flow has few legitimate uses for most users, so disabling it by default removes a powerful account compromise route that attackers have already used in campaigns where victims complete multi factor authentication and then lose their sessions.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP address 38.146.28.75 DNS poisoning response IP address observed in forged DNS replies.
IP address 31.57.243.154 DNS poisoning response IP hosting ms365-device.com, owa-ms365.com, and m365-owa.com.
IP address 104.194.159.150 IP address of ms365-live.com used for Microsoft impersonation lures.
Domain m365-owa.com Attacker controlled domain impersonating Microsoft 365 Outlook Web Access.
Domain owa-ms365.com Attacker controlled domain used in Microsoft 365 credential harvesting pages.
Domain ms365-device.com Attacker controlled domain hosting operator panel and lure content.
Domain ms365-live.com Attacker controlled domain abusing Microsoft device code authentication flow.
Email chikolimdridatgmail.com Registrant email address linked to attacker registered domains.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

The post One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers appeared first on Cyber Security News.






Tushar Subhra Dutta





Go to cyber-security-news





Posted

in

, ,

by