< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 7 sources · 2 days · First seen · Last updated

Categories: TECHNOLOGY

Wi‑Fi DNS hijacks targeting Microsoft 365

Entities: ReliaQuest · BlackFog · APT28 · MedusaHVNC · Microsoft 365

Overview

In late July 2026, security researchers reported a campaign that compromised public Wi‑Fi gateways in hotels, conference centers and airports. By exploiting weak passwords and exposed management interfaces on captive‑portal appliances, attackers poisoned DNS responses and redirected Microsoft 365 login attempts to counterfeit sites. The scheme bypassed multi‑factor authentication by abusing Microsoft’s Device‑Code‑Flow, allowing OAuth tokens to be captured without stealing passwords.

A follow‑up report linked the activity to the Russian‑linked APT28 group, noting similar tactics to the earlier FrostArmada operations. Compromised devices were found in the United States, India, Saudi Arabia and Germany, indicating a broad geographic reach. The same period also saw the emergence of a new remote‑access trojan, MedusaHVNC, offered as malware‑as‑a‑service and employing hidden Windows desktops and encrypted payloads to evade detection. While MedusaHVNC is a separate tool, its discovery highlights the convergence of sophisticated espionage techniques with commercially available ransomware‑style capabilities.

Together, the reports underscore a rising threat to corporate networks from coordinated Wi‑Fi DNS hijacking campaigns that target Microsoft 365 credentials, leveraging both nation‑state actors and commodified malicious tools.

Timeline

  1. 2 days ago

    [TECHNOLOGY] 3 sources
    APT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials, MedusaHVNC RAT uncovered

    APT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials worldwide, while the new MedusaHVNC RAT uses hidden desktops to evade detection.

  2. 4 days ago

    [TECHNOLOGY] 4 sources
    Microsoft-365 Accounts Compromised by Hotel Wi‑Fi DNS Attacks and AI Cloud Security Gaps

    Check Point reports 78% of firms faced AI‑related breaches in 2025, with a large enforcement gap. Meanwhile, hackers hijack hotel Wi‑Fi gateways to redirect Microsoft‑365 logins, bypassing MFA via a DNS and Dev

Sources

b2b-cyber-security.de · blog.clavis.com.br · blogspan.net · borncity.com · c3pb.de · it-boltwise.de · securityaffairs.com