Close Menu
NCIJ Network NCIJ Network
    What's Hot

    NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

    July 28, 2026

    Elon Musk: Humans Will Lose Control of AI Within a Decade

    July 28, 2026

    The best way to save giant sequoias may be more fire

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
    • Elon Musk: Humans Will Lose Control of AI Within a Decade
    • The best way to save giant sequoias may be more fire
    • Johnson & Johnson offers to pay $5.5bn to settle baby powder lawsuits
    • 6 Takeaways From Michigan’s Senate Debate Between Abdul El-Sayed and Haley Stevens
    • OpenAI’s biggest threat may just be open AI
    • New Dysphoria DDoS botnet spreads to 200k devices worldwide
    • SEC warning over crypto yield vaults puts DeFi’s secret human controllers in the crosshairs
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A threat actor has been hacking public Wi-Fi gateway appliances at organizations running captive portal networks to compromise the Microsoft 365 accounts of traveling corporate employees, ReliaQuest reports.

    As part of the attacks, the hackers modified the DNS configurations of the compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure for credential theft.

    Ongoing since at least June 2026, the activity is similar to the previously observed FrostArmada campaign, which was attributed to APT28, also known as Forest Blizzard, and Fancy Bear, a state-sponsored group believed to be linked to Russia’s General Staff Main Intelligence Directorate (GRU).

    Using the adversary-in-the-middle (AitM) technique, the hackers can intercept the victims’ traffic and harvest their credentials and other sensitive information.

    The newly observed activity, ReliaQuest says, involved hacked Wi-Fi gateways at shared venues such as hotels and conference centers across the US, India, and Saudi Arabia.

    The cybersecurity firm warns that any organization running captive Wi-Fi services, including airports, conference centers, healthcare facilities, universities, and event venues, faces a similar attack surface.

    Advertisement. Scroll to continue reading.

    “We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail—confirming this isn’t sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect,” ReliaQuest notes.

    The cybersecurity firm identified four attacker-registered domains used as part of these attacks to deliver Microsoft-impersonation lures.

    Unlike the FrostArmada campaign, the fresh attacks used DNS poisoning to redirect all users to attacker-controlled infrastructure, “potentially an indicator of a less sophisticated or less careful actor than APT28”, ReliaQuest says.

    Overall, the tactics, techniques, and procedures (TTPs) observed in the new campaign suggest that the threat actor has been at least reusing APT28’s tradecraft, but do not fully overlap with FrostArmada.

    “The targeting of captive portal appliances—especially those used in hotels and conference centers—wasn’t previously documented in FrostArmada reporting. Attacker infrastructure also differed from prior FrostArmada activity. The domain registrations and IP addresses used don’t align with infrastructure previously seen in APT28 campaigns,” ReliaQuest notes.

    Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

    Related: Mirai Botnet Targets Flaw in Discontinued D-Link Routers

    Related: China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

    Related: Armored Likho APT Targeting Government, Electric Power Entities

    corporate Credentials Gateways Hacked Harvest public WiFi
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

    Hackers target US firms in FastJson RCE zero-day attacks

    Organise to counter corporate power | Politics

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

    July 28, 2026

    Elon Musk: Humans Will Lose Control of AI Within a Decade

    July 28, 2026

    The best way to save giant sequoias may be more fire

    July 28, 2026

    Johnson & Johnson offers to pay $5.5bn to settle baby powder lawsuits

    July 28, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

    July 28, 2026

    Elon Musk: Humans Will Lose Control of AI Within a Decade

    July 28, 2026

    The best way to save giant sequoias may be more fire

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.