Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

Attackers manipulate DNS settings on hotel and conference center Wi-Fi to redirect users to fraudulent Microsoft 365 login pages, targeting credential theft from business travelers.

Why it matters

This technique exploits trusted public Wi-Fi networks to capture corporate credentials, increasing risk for organizations with mobile employees and demanding enhanced monitoring of authentication attempts originating from such networks.

SOC impact

Investigate authentication logs for unusual or repeated failed Microsoft 365 login attempts tied to hotel or public Wi-Fi IP addresses. Monitor DNS query telemetry for signs of tampering or unexpected redirections. Confirm whether affected assets accessed corporate accounts over compromised networks to assess exposure.

Recommended actions

  1. Review Microsoft 365 login patterns linked to hotel and public Wi-Fi sources
  2. Monitor DNS request logs for anomalies indicating redirection or hijacking
  3. Identify users who accessed corporate accounts from hotel Wi-Fi networks
  4. Analyze network telemetry for suspicious DNS changes on public Wi-Fi devices
  5. Investigate failed authentication attempts from compromised network locations

Executive Summary

Threat actors have been observed altering DNS settings on Wi-Fi devices at hotels and conference centers to redirect users attempting to access Microsoft 365 accounts to fake login pages. This method targets business travelers who use corporate credentials on untrusted networks. By hijacking DNS, attackers create realistic but fraudulent authentication portals aimed at capturing credential information.

Operationally, this attack vector increases the risk of credential theft in environments where users expect connectivity but lack network security controls. Detecting and mitigating such incidents requires focused attention on authentication anomalies from public Wi-Fi IPs and scrutiny of DNS traffic for signs of manipulation. Confirming and tracking affected users and devices is essential to response efforts.

SOC Impact

Investigate authentication logs for unusual or repeated failed Microsoft 365 login attempts tied to hotel or public Wi-Fi IP addresses. Monitor DNS query telemetry for signs of tampering or unexpected redirections. Confirm whether affected assets accessed corporate accounts over compromised networks to assess exposure.

Authentication and Network Activity Validation

  • Review Microsoft 365 login patterns linked to hotel and public Wi-Fi sources
  • Monitor DNS request logs for anomalies indicating redirection or hijacking
  • Identify users who accessed corporate accounts from hotel Wi-Fi networks
  • Analyze network telemetry for suspicious DNS changes on public Wi-Fi devices
  • Investigate failed authentication attempts from compromised network locations

Why It Matters

This technique exploits trusted public Wi-Fi networks to capture corporate credentials, increasing risk for organizations with mobile employees and demanding enhanced monitoring of authentication attempts originating from such networks.

Source