Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 7 sources · 2 days · First seen · Last updated
Categories: TECHNOLOGY
Wi‑Fi DNS hijacks targeting Microsoft 365
Entities: ReliaQuest · BlackFog · APT28 · MedusaHVNC · Microsoft 365
Overview
In late July 2026, security researchers reported a campaign that compromised public Wi‑Fi gateways in hotels, conference centers and airports. By exploiting weak passwords and exposed management interfaces on captive‑portal appliances, attackers poisoned DNS responses and redirected Microsoft 365 login attempts to counterfeit sites. The scheme bypassed multi‑factor authentication by abusing Microsoft’s Device‑Code‑Flow, allowing OAuth tokens to be captured without stealing passwords.
A follow‑up report linked the activity to the Russian‑linked APT28 group, noting similar tactics to the earlier FrostArmada operations. Compromised devices were found in the United States, India, Saudi Arabia and Germany, indicating a broad geographic reach. The same period also saw the emergence of a new remote‑access trojan, MedusaHVNC, offered as malware‑as‑a‑service and employing hidden Windows desktops and encrypted payloads to evade detection. While MedusaHVNC is a separate tool, its discovery highlights the convergence of sophisticated espionage techniques with commercially available ransomware‑style capabilities.
Together, the reports underscore a rising threat to corporate networks from coordinated Wi‑Fi DNS hijacking campaigns that target Microsoft 365 credentials, leveraging both nation‑state actors and commodified malicious tools.
Timeline
-
2 days ago
[TECHNOLOGY] 3 sourcesAPT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials, MedusaHVNC RAT uncoveredAPT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials worldwide, while the new MedusaHVNC RAT uses hidden desktops to evade detection.
-
4 days ago
[TECHNOLOGY] 4 sourcesMicrosoft-365 Accounts Compromised by Hotel Wi‑Fi DNS Attacks and AI Cloud Security GapsCheck Point reports 78% of firms faced AI‑related breaches in 2025, with a large enforcement gap. Meanwhile, hackers hijack hotel Wi‑Fi gateways to redirect Microsoft‑365 logins, bypassing MFA via a DNS and Dev
Sources
b2b-cyber-security.de · blog.clavis.com.br · blogspan.net · borncity.com · c3pb.de · it-boltwise.de · securityaffairs.com