Hotel Wi-Fi Phishing Attack Targets Business Logins
Hackers are targeting hotel Wi-Fi networks to phish business logins by compromising Wi-Fi gateways and altering DNS settings. The campaign, which has been active since at least June, affects hotels in several U.S. cities.
The attackers change the gateway's Domain Name System (DNS) settings, directing browsers to fake Microsoft login pages when a user tries to open a legitimate one. This makes it difficult for users to notice the attack before entering sensitive information.
ReliaQuest, a cybersecurity company, has identified four domains used by the attackers: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. These domains contain familiar Microsoft terms, making them harder to spot.
The attack can bypass multifactor authentication (MFA) if a user approves an unfamiliar device code request. Researchers also spotted attempts to abuse Web Proxy Auto-Discovery (WPAD), which could send traffic from Windows applications through a malicious proxy controlled by the hackers.