Hackers are compromising hotel and conference-centre Wi-Fi gateways to redirect guests to fake Microsoft 365 login pages. The campaign appears to target travelling employees across several industries, putting business emails, documents and other sensitive data at risk.

Researchers identified compromised Wi-Fi devices in several US cities, as well as locations in India and Saudi Arabia. Affected organisations span financial services, legal, healthcare, energy, retail and professional services.

Attackers change Wi-Fi DNS settings

The attackers gain administrator-level access to Wi-Fi gateways, although the initial entry point remains unclear. Possible methods include exposed or weakly protected management interfaces, such as SSH, SNMP and web administration panels, or unpatched vulnerabilities.

After gaining access, the attackers alter the gateway’s DNS settings. This lets them redirect visitors attempting to reach legitimate Microsoft login services to phishing infrastructure instead.

Researchers found at least four domains used for fake Microsoft 365 login portals:

  • m365-owa[.]com
  • owa-ms365[.]com
  • ms365-device[.]com
  • ms365-live[.]com

As a result, users may believe they are signing in to Microsoft 365 while entering their credentials on an attacker-controlled page.

Device-code prompts can bypass MFA

In some cases, the attackers used a fraudulent device-code authentication flow. Victims were redirected to a fake Microsoft page and asked to approve a login prompt.

Approving it does not simply confirm the user’s own login. Instead, it can authorise a session initiated by the attacker, allowing a legitimate OAuth token to be issued to the attacker’s device.

This method can bypass multi-factor authentication without requiring the attackers to steal passwords or intercept existing access tokens.

WPAD abuse was also attempted

In around one-third of the investigated incidents, the attackers attempted to exploit Web Proxy Auto-Discovery, known as WPAD.

They responded to Windows’ automatic WPAD requests with a malicious proxy auto-configuration file. If successful, this could route traffic from Windows applications, including Chrome, through an attacker-controlled proxy.

Researchers could not confirm whether those proxy attacks succeeded.

Public DNS alone will not stop the attack

Using a public DNS service, such as Google’s 8.8.8.8, does not necessarily prevent these hotel Wi-Fi DNS hijacks. The compromised gateway can forge unencrypted DNS requests before they ever reach the chosen resolver.

Travellers and organisations should use an always-on, full-tunnel VPN alongside encrypted DNS in strict mode. Security teams should also disable WPAD where possible, review logs for suspicious authentication activity, and turn off Microsoft Entra ID Device Code authentication when it is not required.


0 responses to “Hotel Wi-Fi DNS Hijacks Target Microsoft 365 Accounts”