Close Menu
  • US
  • World
    • Canada
    • Europe
    • Asia
    • Africa
    • Australia
    • South America
  • Politics
  • Business
    • Finance
    • Investing
    • Markets
    • Economy
    • Small Business
    • Crypto
  • Money
  • Lifestyle
  • Sports
  • Videos
  • Topics
    • Entertainment
    • Health
    • Tech
    • Travel
  • More Articles
Trending Now
Inside Ford’s 3-million-square-foot Louisville plant transformation

Inside Ford’s 3-million-square-foot Louisville plant transformation

August 13, 2026
EU budget: Sweden, a ‘frugal’ state, set to turn more hawkish

EU budget: Sweden, a ‘frugal’ state, set to turn more hawkish

August 13, 2026
What to do in Burgas, Bulgaria’s seaside gem and Eurovision host city

What to do in Burgas, Bulgaria’s seaside gem and Eurovision host city

August 13, 2026
City of Edmonton offers incentives to encourage transit-oriented development

City of Edmonton offers incentives to encourage transit-oriented development

August 13, 2026
How federal compliance is blocking Iranian PhD and master’s candidates

How federal compliance is blocking Iranian PhD and master’s candidates

August 13, 2026
Facebook X (Twitter) Instagram
Just In
  • Inside Ford’s 3-million-square-foot Louisville plant transformation
  • EU budget: Sweden, a ‘frugal’ state, set to turn more hawkish
  • What to do in Burgas, Bulgaria’s seaside gem and Eurovision host city
  • City of Edmonton offers incentives to encourage transit-oriented development
  • How federal compliance is blocking Iranian PhD and master’s candidates
  • David Foster Addresses Viral Rumors He Snubbed Meghan Markle at Star-Studded Charity Event
  • Fox News ‘Antisemitism Exposed’ Newsletter: Why Jews hold the key to Michigan Senate race
  • GOP congressman’s ex-wife sues, alleging sensitive image of 2-year-old daughter was posted online
  • Privacy
  • Terms
  • Advertise
  • Contact
Pure Info NewsPure Info News
Newsletter
  • US
  • World
    • Canada
    • Europe
    • Asia
    • Africa
    • Australia
    • South America
  • Politics
  • Business
    • Finance
    • Investing
    • Markets
    • Economy
    • Small Business
    • Crypto
  • Money
  • Lifestyle
  • Sports
  • Videos
  • Topics
    • Entertainment
    • Health
    • Tech
    • Travel
  • More Articles
 Markets Login
Pure Info NewsPure Info News
Home » DNS Poisoning Campaign Targets Hospitality Wi-Fi
Tech

DNS Poisoning Campaign Targets Hospitality Wi-Fi

News RoomNews RoomAugust 13, 2026No Comments
Facebook Twitter WhatsApp Telegram Pinterest Email
DNS Poisoning Campaign Targets Hospitality Wi-Fi

In what appears to be a state-sponsored credential theft campaign, a group of network marauders has been targeting Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack corporate travelers’ accounts.

Once the threat actors control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, according to a report by ReliaQuest, a global security operations and threat response automation company.

According to ReliaQuest, the activity has been ongoing since at least June 2026.

The compromised devices investigated by ReliaQuest were appliances primarily used at hotels and other organizations running captive Wi-Fi services, explained the report authored by researchers Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie and Connor Short.

The researchers said, with “low-to-medium confidence,” that the attackers likely gained initial access through exposed management interfaces combined with weak or reused administrative credentials, although limited visibility into the compromised devices prevented them from confirming that assessment.

That methodology would be consistent with the gateway targeting and DNS poisoning patterns documented in recent reporting on an APT28-linked campaign known as “FrostArmada,” the report noted.

FrostArmada, a cyberespionage campaign linked to the Russian threat group Forest Blizzard, also known as APT28 and Fancy Bear, hijacked DNS settings on compromised routers to redirect authentication traffic and steal Microsoft credentials and OAuth tokens. It was disrupted in April 2026 through a joint operation involving law enforcement and private-sector partners.

The report explained that once the attacker compromised the gateway devices, they modified their configurations and used DNS poisoning to redirect regular web traffic, funneling connections for legitimate domains through attacker-controlled infrastructure.

Stealthy Attack

“Hotels and conference centers are not random targets,” observed James Edwards, senior director of engineering at Keeper Security, a password management and online storage company in Chicago.

“These are environments where senior executives, legal teams, financial professionals and other high-value corporate employees routinely connect to shared Wi-Fi without thinking twice about it,” he told TechNewsWorld.

“A single compromised gateway at a major industry conference gives an attacker access to hundreds — or even thousands — of corporate devices from a range of organizations,” he explained. “The infrastructure economics are extraordinary.”

“What makes this campaign particularly dangerous is that it operates entirely below the user’s awareness,” he continued. “When an attacker owns the gateway, they don’t need to touch a single endpoint, send a single phishing email or plant a single piece of malware.”

“DNS poisoning redirects traffic silently,” he added. “The user browses normally, enters credentials normally and has no reason to suspect anything is wrong.”

Concerning Attack Technique

These attacks are becoming increasingly common, noted Denis Calderone, principal and CTO of Suzu Labs, a provider of AI-powered cybersecurity services in Las Vegas.

“This is basically the same playbook as what APT28 did with 18,000 home routers in the FrostArmada campaign back in April,” he told TechNewsWorld. “In this case, the attacker is targeting legitimate hotel Wi-Fi gateways.”

One particularly concerning aspect of the campaign involves device-code authentication abuse, in which the user is redirected to what appears to be a legitimate Microsoft authorization prompt.

“If the user approves it, it actually authorizes a session the attacker initiated,” he said. “Microsoft issues a valid OAuth token to the attacker’s client, and that token is already MFA-satisfied. No credentials stolen. No tokens intercepted. MFA completely bypassed.”

“Device-code authentication was designed for input-constrained devices like smart TVs and conference room displays, but it’s enabled by default in Microsoft’s Entra ID service, and many enterprises have never turned it off because they don’t know it’s there,” he explained.

He recommended disabling the service via Conditional Access for all users except the handful of service accounts or device groups that genuinely need it.

Long-Expected Attack Becomes Reality

“What surprises me most isn’t the technique, it’s the timeline,” observed Larry Pesce, vice president of services at Columbus, Ohio-based Finite State, which automates security compliance and analysis for connected device manufacturers.

“Security researchers have been demonstrating and warning about exactly this class of attack for the better part of a decade,” he told TechNewsWorld. “What’s new here isn’t the method. It’s that we finally have large-scale, in-the-wild evidence that real threat actors are operationalizing it.”

“The gap between ‘we know this is possible’ and ‘we can prove it’s happening’ just closed, and that should worry anyone who travels for work,” he said.

He added that understanding the threat actors in the campaign can be worthwhile.

“If this is APT28 or something in that orbit, the interesting shift is who they went after,” he noted. “Groups like this have historically been surgical, redirecting only traffic that matched specific keywords or targets. What researchers describe here is the opposite: non-selective redirection that scooped up anyone who connected.”

“The takeaway here isn’t ‘I’m not important enough to be a target,'” he warned. “On a shared, compromised network, importance is decided after the fact. You give up the credential first, and someone else decides later how to monetize or weaponize it.”

“That’s exactly why hygiene matters for everyone, not just the executives and the obvious high-risk roles,” he added. “The person who assumes they’re not worth targeting is often the easiest way in.”

Changing Targeting Strategy

Seemant Sehgal, CEO and founder of BreachLock, a penetration testing company in New York City, maintained that the campaign relied less on sophisticated techniques than on weak security practices at the targeted gateways.

“The failure point here is that these gateways were reachable with credentials that could be compromised in the first place, and whatever monitoring existed on them was not watching for configuration changes,” he told TechNewsWorld.

Keeper Security’s Edwards acknowledged that DNS-based attacks are not new but added that they have historically required access to upstream infrastructure or individual device compromise.

“What has changed is the targeting model,” he explained. “Attacking shared network gateways in high-traffic venues turns a single point of compromise into a force multiplier, where one router yields access to hundreds of corporate devices across dozens of organizations simultaneously.”

Weaponizing Trust

“That expansion from home office and small business networks into the hospitality environments that corporate employees move through every day represents a meaningful shift in both who is exposed and how little warning they receive,” he said.

“What this campaign exposes, more than any specific technique, is how thoroughly attackers have learned to weaponize trust,” he argued.

“The hotel network is trusted because the hotel provides it,” he noted. “The Microsoft sign-in prompt is trusted because it looks exactly right. The OAuth authorization is trusted because it is, technically, legitimate.”

“None of those assumptions hold in an environment where the infrastructure itself has been compromised,” he continued. “The real lesson here is not that a new attack technique has emerged, but that the perimeter organizations believed they were operating inside does not exist the moment an employee connects to a network they don’t control.”

“The organizations that come through this kind of campaign intact are the ones that have already stopped extending implicit trust to infrastructure they don’t own,” he added. “That is not a new principle. It is simply one the hospitality sector, and the enterprises whose employees travel through it, can no longer afford to defer.”

According to ReliaQuest, organizations can significantly reduce their exposure by requiring corporate devices to use always-on, full-tunnel VPNs that route DNS requests through trusted corporate infrastructure before they reach hotel or conference-center gateways.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram WhatsApp Email

Related News

Nvidia’s Long-Term Strategy Could Open the Door for AMD

Nvidia’s Long-Term Strategy Could Open the Door for AMD

FBI, EPA Warn of Cyberattacks Targeting Water Infrastructure

FBI, EPA Warn of Cyberattacks Targeting Water Infrastructure

HP Needs More Than a New CEO

HP Needs More Than a New CEO

Billions of Stolen Browser Cookies Fuel Account Hijacking Risks

Billions of Stolen Browser Cookies Fuel Account Hijacking Risks

Multi-Model AI Could Improve Enterprise Trust

Multi-Model AI Could Improve Enterprise Trust

AI Rules to Protect Kids Risk Repeating Social Media Mistakes

AI Rules to Protect Kids Risk Repeating Social Media Mistakes

Elon Musk’s Moneyless Future Faces a Reality Check

Elon Musk’s Moneyless Future Faces a Reality Check

Zuckerberg Makes His Case for Superintelligence for All

Zuckerberg Makes His Case for Superintelligence for All

An Upgrade I Never Expected

Add A Comment
Leave A Reply Cancel Reply

Editors Picks

EU budget: Sweden, a ‘frugal’ state, set to turn more hawkish

EU budget: Sweden, a ‘frugal’ state, set to turn more hawkish

August 13, 2026
What to do in Burgas, Bulgaria’s seaside gem and Eurovision host city

What to do in Burgas, Bulgaria’s seaside gem and Eurovision host city

August 13, 2026
City of Edmonton offers incentives to encourage transit-oriented development

City of Edmonton offers incentives to encourage transit-oriented development

August 13, 2026
How federal compliance is blocking Iranian PhD and master’s candidates

How federal compliance is blocking Iranian PhD and master’s candidates

August 13, 2026
David Foster Addresses Viral Rumors He Snubbed Meghan Markle at Star-Studded Charity Event

David Foster Addresses Viral Rumors He Snubbed Meghan Markle at Star-Studded Charity Event

August 13, 2026

Latest News

Fox News ‘Antisemitism Exposed’ Newsletter: Why Jews hold the key to Michigan Senate race

Fox News ‘Antisemitism Exposed’ Newsletter: Why Jews hold the key to Michigan Senate race

August 13, 2026
GOP congressman’s ex-wife sues, alleging sensitive image of 2-year-old daughter was posted online

GOP congressman’s ex-wife sues, alleging sensitive image of 2-year-old daughter was posted online

August 13, 2026
Ancient mummy DNA reveals chilling clue to deadly disease that swept the Americas

Ancient mummy DNA reveals chilling clue to deadly disease that swept the Americas

August 13, 2026

Subscribe to News

Get the latest US news and updates directly to your inbox.

Advertisement
Demo
Facebook X (Twitter) Pinterest TikTok Instagram
2026 © Prices.com LLC. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Press Release
  • For Advertisers
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?