< Back to all clusters
[TECHNOLOGY] · United States, India, Saudi Arabia, Germany · 3 sources

APT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials, MedusaHVNC RAT uncovered

Malicious actors have been compromising public Wi‑Fi gateways that use captive portals in hotels, convention centers and airports to intercept Microsoft 365 login credentials. The campaign, observed since June 2026, redirects users through DNS poisoning to fraudulent pages that mimic Microsoft sign‑in screens, targeting traveling employees across sectors such as finance, legal, health, energy, retail and professional services. Compromised devices were found in the United States, India and Saudi Arabia, and the operation shows similarities to the previously identified FrostArmada activity attributed to the Russian‑linked APT28 group.

Separately, security researchers have identified a new remote‑access trojan called MedusaHVNC. Distributed as malware‑as‑a‑service, the RAT runs hidden Windows desktops to hide its activity, uses legitimate system tools like wscript.exe for execution, and encrypts its payload to evade detection. Infection requires user interaction and follows a multi‑stage chain designed to bypass basic behavioral security controls. The discovery highlights an evolving threat landscape where sophisticated evasion techniques are combined with targeted credential harvesting.

Both incidents underscore growing risks for corporate networks from advanced cyber‑espionage groups and commercially available ransomware‑style tools.

Entities: APT28 · BlackFog · MedusaHVNC · Microsoft 365 · ReliaQuest