Threat IntelligenceBleeping Computer
8.0 — CRITICAL
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A global campaign targeting hospitality Wi-Fi networks has been linked to the Russian threat actor Midnight Blizzard, using custom malware to breach Microsoft 365 accounts with capabilities for persistent access, credential theft, surveillance, and data exfiltration.
⚙️Technical Details
Affected Systems
Windows devicesAndroid devices
Attack Vectors
Manipulation of DNS settings on networks served by captive portal equipmentRedirecting victims to phishing pages impersonating Microsoft 365 login portals or device code phishing pagesDelivery of malware via fake browser and operating system update pages
💥Impact Assessment
Severity: high
Who Is at Risk
hotel and conference center Wi-Fi usersMicrosoft 365 account holdersSeverity: high
🛡️Recommended Actions
1Treat hotel and conference Wi-Fi as untrusted
2Use private cellular or managed connections whenever possible
3Avoid software updates or tools offered through captive portals
📦Affected Products
Windows devicesAndroid devices
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
