Hotel Wi-Fi Networks Compromised for Microsoft Login Hacks
Hackers have been compromising hotel Wi-Fi networks to target Microsoft logins. This campaign has been active since at least June, according to cybersecurity company ReliaQuest.
The attackers alter the Domain Name System (DNS) settings of compromised Wi-Fi gateways, which directs users to fake Microsoft login pages. The hackers may gain access by exploiting weak passwords or poorly protected remote management services.
ReliaQuest identified several possible entry points for the attackers, including exposed administrative tools and older software with known security flaws. Once inside, the hacker can change the DNS configuration without affecting individual devices.
The fake Microsoft pages collect business logins, which may expose sensitive information such as company emails and cloud services. The attackers also use a device code authentication flow to bypass multifactor authentication. Users should be cautious when approving unfamiliar device codes and verify login addresses before entering passwords.