Close Menu
NCIJ Network NCIJ Network
    What's Hot

    France and Spain continue to battle fires as new heatwave looms

    July 28, 2026

    Political chaos turns spotlight on Romania’s MAGA champion – POLITICO

    July 28, 2026

    Success of India’s ‘cockroach’ protests energises critics of Narendra Modi’s government

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • France and Spain continue to battle fires as new heatwave looms
    • Political chaos turns spotlight on Romania’s MAGA champion – POLITICO
    • Success of India’s ‘cockroach’ protests energises critics of Narendra Modi’s government
    • Nanoleaf’s colorful pegboard and shelf kit is half off
    • Arista patches VeloCloud Orchestrator zero-day exploited in attacks
    • Hong Kong Prepares Banks for Quantum Threats
    • Why the same DNA damage causes cancer in some people but not others
    • More than 100 queen ants destined for Laos seized in Mexico
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A threat actor has been hacking public Wi-Fi gateway appliances at organizations running captive portal networks to compromise the Microsoft 365 accounts of traveling corporate employees, ReliaQuest reports.

    As part of the attacks, the hackers modified the DNS configurations of the compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure for credential theft.

    Ongoing since at least June 2026, the activity is similar to the previously observed FrostArmada campaign, which was attributed to APT28, also known as Forest Blizzard, and Fancy Bear, a state-sponsored group believed to be linked to Russia’s General Staff Main Intelligence Directorate (GRU).

    Using the adversary-in-the-middle (AitM) technique, the hackers can intercept the victims’ traffic and harvest their credentials and other sensitive information.

    The newly observed activity, ReliaQuest says, involved hacked Wi-Fi gateways at shared venues such as hotels and conference centers across the US, India, and Saudi Arabia.

    The cybersecurity firm warns that any organization running captive Wi-Fi services, including airports, conference centers, healthcare facilities, universities, and event venues, faces a similar attack surface.

    Advertisement. Scroll to continue reading.

    “We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail—confirming this isn’t sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect,” ReliaQuest notes.

    The cybersecurity firm identified four attacker-registered domains used as part of these attacks to deliver Microsoft-impersonation lures.

    Unlike the FrostArmada campaign, the fresh attacks used DNS poisoning to redirect all users to attacker-controlled infrastructure, “potentially an indicator of a less sophisticated or less careful actor than APT28”, ReliaQuest says.

    Overall, the tactics, techniques, and procedures (TTPs) observed in the new campaign suggest that the threat actor has been at least reusing APT28’s tradecraft, but do not fully overlap with FrostArmada.

    “The targeting of captive portal appliances—especially those used in hotels and conference centers—wasn’t previously documented in FrostArmada reporting. Attacker infrastructure also differed from prior FrostArmada activity. The domain registrations and IP addresses used don’t align with infrastructure previously seen in APT28 campaigns,” ReliaQuest notes.

    Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

    Related: Mirai Botnet Targets Flaw in Discontinued D-Link Routers

    Related: China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

    Related: Armored Likho APT Targeting Government, Electric Power Entities

    corporate Credentials Gateways Hacked Harvest public WiFi
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

    Hackers target US firms in FastJson RCE zero-day attacks

    Organise to counter corporate power | Politics

    What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

    Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    France and Spain continue to battle fires as new heatwave looms

    July 28, 2026

    Political chaos turns spotlight on Romania’s MAGA champion – POLITICO

    July 28, 2026

    Success of India’s ‘cockroach’ protests energises critics of Narendra Modi’s government

    July 28, 2026

    Nanoleaf’s colorful pegboard and shelf kit is half off

    July 28, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    France and Spain continue to battle fires as new heatwave looms

    July 28, 2026

    Political chaos turns spotlight on Romania’s MAGA champion – POLITICO

    July 28, 2026

    Success of India’s ‘cockroach’ protests energises critics of Narendra Modi’s government

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.