• Home
  • News
  • World
  • Business
  • Politics
  • Tech
  • Entertainment
  • Health
  • Lifestyle
  • Sports
  • Travel
  • More
    • Web stories
    • Trending
    • Press Release

Subscribe to Updates

Get the latest USA News and updates directly to your inbox.

What's On
Kenny Omega warns Will Ospreay that his loose alliances has made him ‘sloppy’ ahead of AEW All In title clash

Kenny Omega warns Will Ospreay that his loose alliances has made him ‘sloppy’ ahead of AEW All In title clash

August 13, 2026
Exclusive | My wild weekend at summer camp for NYC grownups — 15 years after I dreaded it as a kid

Exclusive | My wild weekend at summer camp for NYC grownups — 15 years after I dreaded it as a kid

August 13, 2026
‘Camp Rock 3’: Liamani Segura, Malachi Barton on stepping into more ‘grounded’ lead roles, heartfelt advice from Demi Lovato

‘Camp Rock 3’: Liamani Segura, Malachi Barton on stepping into more ‘grounded’ lead roles, heartfelt advice from Demi Lovato

August 13, 2026
Explosion at Dutch port of Rotterdam leaves one dead, police say

Explosion at Dutch port of Rotterdam leaves one dead, police say

August 13, 2026
Revealed: Europe’s best-value cities for a weekend break

Revealed: Europe’s best-value cities for a weekend break

August 13, 2026
Facebook X (Twitter) Instagram
Just In
  • Kenny Omega warns Will Ospreay that his loose alliances has made him ‘sloppy’ ahead of AEW All In title clash
  • Exclusive | My wild weekend at summer camp for NYC grownups — 15 years after I dreaded it as a kid
  • ‘Camp Rock 3’: Liamani Segura, Malachi Barton on stepping into more ‘grounded’ lead roles, heartfelt advice from Demi Lovato
  • Explosion at Dutch port of Rotterdam leaves one dead, police say
  • Revealed: Europe’s best-value cities for a weekend break
  • Forget Wide-Leg Pants — Pleated Trousers Are the New ‘It’ Style Taking Over Rich Mom Closets
  • ROMERO & JULIET Featuring Kate Rockwell and Jack Baugh Out Now
  • Minnesota fraud scandal will haunt Flanagan in high-stakes Senate race, top House Republican warns
  • Privacy Policy
  • Advertise
  • Contact
US Times MirrorUS Times Mirror
Newsletter
  • Home
  • News
  • World
  • Business
  • Politics
  • Tech
  • Entertainment
  • Health
  • Lifestyle
  • Sports
  • Travel
  • More
    • Web stories
    • Trending
    • Press Release
 Weather Login
US Times MirrorUS Times Mirror
Home » DNS Poisoning Campaign Targets Hospitality Wi-Fi
Tech

DNS Poisoning Campaign Targets Hospitality Wi-Fi

staffstaffAugust 13, 20262 ViewsNo Comments
Facebook Twitter WhatsApp Telegram Pinterest Email
DNS Poisoning Campaign Targets Hospitality Wi-Fi

In what appears to be a state-sponsored credential theft campaign, a group of network marauders has been targeting Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack corporate travelers’ accounts.

Once the threat actors control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, according to a report by ReliaQuest, a global security operations and threat response automation company.

According to ReliaQuest, the activity has been ongoing since at least June 2026.

The compromised devices investigated by ReliaQuest were appliances primarily used at hotels and other organizations running captive Wi-Fi services, explained the report authored by researchers Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie and Connor Short.

The researchers said, with “low-to-medium confidence,” that the attackers likely gained initial access through exposed management interfaces combined with weak or reused administrative credentials, although limited visibility into the compromised devices prevented them from confirming that assessment.

That methodology would be consistent with the gateway targeting and DNS poisoning patterns documented in recent reporting on an APT28-linked campaign known as “FrostArmada,” the report noted.

FrostArmada, a cyberespionage campaign linked to the Russian threat group Forest Blizzard, also known as APT28 and Fancy Bear, hijacked DNS settings on compromised routers to redirect authentication traffic and steal Microsoft credentials and OAuth tokens. It was disrupted in April 2026 through a joint operation involving law enforcement and private-sector partners.

The report explained that once the attacker compromised the gateway devices, they modified their configurations and used DNS poisoning to redirect regular web traffic, funneling connections for legitimate domains through attacker-controlled infrastructure.

Stealthy Attack

“Hotels and conference centers are not random targets,” observed James Edwards, senior director of engineering at Keeper Security, a password management and online storage company in Chicago.

“These are environments where senior executives, legal teams, financial professionals and other high-value corporate employees routinely connect to shared Wi-Fi without thinking twice about it,” he told TechNewsWorld.

“A single compromised gateway at a major industry conference gives an attacker access to hundreds — or even thousands — of corporate devices from a range of organizations,” he explained. “The infrastructure economics are extraordinary.”

“What makes this campaign particularly dangerous is that it operates entirely below the user’s awareness,” he continued. “When an attacker owns the gateway, they don’t need to touch a single endpoint, send a single phishing email or plant a single piece of malware.”

“DNS poisoning redirects traffic silently,” he added. “The user browses normally, enters credentials normally and has no reason to suspect anything is wrong.”

Concerning Attack Technique

These attacks are becoming increasingly common, noted Denis Calderone, principal and CTO of Suzu Labs, a provider of AI-powered cybersecurity services in Las Vegas.

“This is basically the same playbook as what APT28 did with 18,000 home routers in the FrostArmada campaign back in April,” he told TechNewsWorld. “In this case, the attacker is targeting legitimate hotel Wi-Fi gateways.”

One particularly concerning aspect of the campaign involves device-code authentication abuse, in which the user is redirected to what appears to be a legitimate Microsoft authorization prompt.

“If the user approves it, it actually authorizes a session the attacker initiated,” he said. “Microsoft issues a valid OAuth token to the attacker’s client, and that token is already MFA-satisfied. No credentials stolen. No tokens intercepted. MFA completely bypassed.”

“Device-code authentication was designed for input-constrained devices like smart TVs and conference room displays, but it’s enabled by default in Microsoft’s Entra ID service, and many enterprises have never turned it off because they don’t know it’s there,” he explained.

He recommended disabling the service via Conditional Access for all users except the handful of service accounts or device groups that genuinely need it.

Long-Expected Attack Becomes Reality

“What surprises me most isn’t the technique, it’s the timeline,” observed Larry Pesce, vice president of services at Columbus, Ohio-based Finite State, which automates security compliance and analysis for connected device manufacturers.

“Security researchers have been demonstrating and warning about exactly this class of attack for the better part of a decade,” he told TechNewsWorld. “What’s new here isn’t the method. It’s that we finally have large-scale, in-the-wild evidence that real threat actors are operationalizing it.”

“The gap between ‘we know this is possible’ and ‘we can prove it’s happening’ just closed, and that should worry anyone who travels for work,” he said.

He added that understanding the threat actors in the campaign can be worthwhile.

“If this is APT28 or something in that orbit, the interesting shift is who they went after,” he noted. “Groups like this have historically been surgical, redirecting only traffic that matched specific keywords or targets. What researchers describe here is the opposite: non-selective redirection that scooped up anyone who connected.”

“The takeaway here isn’t ‘I’m not important enough to be a target,'” he warned. “On a shared, compromised network, importance is decided after the fact. You give up the credential first, and someone else decides later how to monetize or weaponize it.”

“That’s exactly why hygiene matters for everyone, not just the executives and the obvious high-risk roles,” he added. “The person who assumes they’re not worth targeting is often the easiest way in.”

Changing Targeting Strategy

Seemant Sehgal, CEO and founder of BreachLock, a penetration testing company in New York City, maintained that the campaign relied less on sophisticated techniques than on weak security practices at the targeted gateways.

“The failure point here is that these gateways were reachable with credentials that could be compromised in the first place, and whatever monitoring existed on them was not watching for configuration changes,” he told TechNewsWorld.

Keeper Security’s Edwards acknowledged that DNS-based attacks are not new but added that they have historically required access to upstream infrastructure or individual device compromise.

“What has changed is the targeting model,” he explained. “Attacking shared network gateways in high-traffic venues turns a single point of compromise into a force multiplier, where one router yields access to hundreds of corporate devices across dozens of organizations simultaneously.”

Weaponizing Trust

“That expansion from home office and small business networks into the hospitality environments that corporate employees move through every day represents a meaningful shift in both who is exposed and how little warning they receive,” he said.

“What this campaign exposes, more than any specific technique, is how thoroughly attackers have learned to weaponize trust,” he argued.

“The hotel network is trusted because the hotel provides it,” he noted. “The Microsoft sign-in prompt is trusted because it looks exactly right. The OAuth authorization is trusted because it is, technically, legitimate.”

“None of those assumptions hold in an environment where the infrastructure itself has been compromised,” he continued. “The real lesson here is not that a new attack technique has emerged, but that the perimeter organizations believed they were operating inside does not exist the moment an employee connects to a network they don’t control.”

“The organizations that come through this kind of campaign intact are the ones that have already stopped extending implicit trust to infrastructure they don’t own,” he added. “That is not a new principle. It is simply one the hospitality sector, and the enterprises whose employees travel through it, can no longer afford to defer.”

According to ReliaQuest, organizations can significantly reduce their exposure by requiring corporate devices to use always-on, full-tunnel VPNs that route DNS requests through trusted corporate infrastructure before they reach hotel or conference-center gateways.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram WhatsApp Email

Related News

Nvidia’s Long-Term Strategy Could Open the Door for AMD

Nvidia’s Long-Term Strategy Could Open the Door for AMD

FBI, EPA Warn of Cyberattacks Targeting Water Infrastructure

FBI, EPA Warn of Cyberattacks Targeting Water Infrastructure

HP Needs More Than a New CEO

HP Needs More Than a New CEO

Billions of Stolen Browser Cookies Fuel Account Hijacking Risks

Billions of Stolen Browser Cookies Fuel Account Hijacking Risks

Multi-Model AI Could Improve Enterprise Trust

Multi-Model AI Could Improve Enterprise Trust

Elon Musk’s Moneyless Future Faces a Reality Check

Elon Musk’s Moneyless Future Faces a Reality Check

AI Rules to Protect Kids Risk Repeating Social Media Mistakes

AI Rules to Protect Kids Risk Repeating Social Media Mistakes

Zuckerberg Makes His Case for Superintelligence for All

Zuckerberg Makes His Case for Superintelligence for All

An Upgrade I Never Expected

An Upgrade I Never Expected

Add A Comment

Leave A Reply Cancel Reply

Latest News

Review: Record Shares of Voters Turned Out for 2020 election

Review: Record Shares of Voters Turned Out for 2020 election

January 11, 2021
EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

January 11, 2021
World’s Most Advanced Oil Rig Commissioned at ONGC Well

World’s Most Advanced Oil Rig Commissioned at ONGC Well

January 11, 2021
Melbourne: All Refugees Held in Hotel Detention to be Released

Melbourne: All Refugees Held in Hotel Detention to be Released

January 11, 2021

Subscribe to News

Get the latest USA News and updates directly to your inbox.

Editor's Picks
Review: Record Shares of Voters Turned Out for 2020 election

Review: Record Shares of Voters Turned Out for 2020 election

January 11, 2021
EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

January 11, 2021
World’s Most Advanced Oil Rig Commissioned at ONGC Well

World’s Most Advanced Oil Rig Commissioned at ONGC Well

January 11, 2021
Facebook X (Twitter) Pinterest WhatsApp TikTok Instagram
2026 © US Times Mirror. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?