Affected Systems
Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, India, and Saudi Arabia. Targets traveling employees from financial services, professional services, legal, healthcare, energy, and retail sectors accessing Microsoft 365. Campaign active since at least June 2026.
Exploitation Status
Active exploitation confirmed. ReliaQuest observed compromised Wi-Fi gateways redirecting traffic to attacker-controlled domains (m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, ms365-live[.]com). Campaign attributed with similarity to APT28 (Fancy Bear) tactics.
Business Impact
Attackers gain access to Microsoft 365 accounts, including email, documents, and business communications. Device-code authentication flow abuse bypasses MFA without credential theft by obtaining legitimate OAuth tokens. Public DNS (e.g., 8.8.8.8) does not prevent the attack as DNS requests are forged at the gateway level. WPAD abuse attempts observed in one-third of cases to route traffic through attacker-controlled proxies.
Urgency
🟠Within 24 hours
Recommended Actions
- Deploy always-on, full-tunnel VPN for all traveling employees connecting to untrusted networks
- Enable encrypted DNS in strict mode (DNS-over-HTTPS or DNS-over-TLS) on corporate endpoints
- Disable Device Code authentication flow in Microsoft Entra ID unless specifically required for business operations
- Disable WPAD (Web Proxy Auto-Discovery) via Group Policy on all Windows endpoints
- Monitor Microsoft 365 sign-in logs for OAuth token grants from unexpected locations or device types, especially following travel to hotels or conferences
- Block known malicious domains: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, ms365-live[.]com
