IT security researchers have discovered compromised Wi-Fi access points in hotels, conference centers, and other shared environments. Attackers, located in Russia, are said to have redirected traffic and thereby stolen access credentials for Microsoft 365. The attacks have reportedly been ongoing since June of this year.

This is reported by the IT security firm ReliaQuest in a blog post. The Russian cyber gang known as APT28, also referred to as “Fancy Bear” or “Forest Blizzard”, has been linked to similar attacks before. Now, it is said to be employing DNS poisoning to redirect regular web traffic and steal victims' credentials through fake login pages for Microsoft 365.

The Wi-Fi routers and access points were likely attacked via accessible management interfaces, with IT researchers also mentioning SSH, SNMP, and web management interfaces. Analysts cannot confirm this with certainty, but it aligns with the previously observed pattern in the Fancy Bear attack campaign “FrostArmada”. In this campaign, attackers alter device configurations to redirect requests to infrastructure they control. Researchers have found compromised devices in several cities in the USA, as well as in India and Saudi Arabia. The redirected traffic affects many sectors, including financial services, healthcare, the legal field, energy, and retail. The attacks therefore appear to target all traveling employees.