Hacked Public Wi-Fi Gateways: How Cybercriminals Steal Corporate Credentials
Public Wi-Fi Gateways Exploited to Steal Corporate Credentials
A cyber threat actor has been compromising public Wi-Fi gateway devices at organizations utilizing captive portal networks to infiltrate Microsoft 365 accounts of remote corporate employees, according to a report from ReliaQuest.
Campaign Details and Tactics
The attackers have been altering DNS settings on small office/home office (SOHO) routers to reroute user traffic to malicious infrastructure designed to capture login credentials. This activity has been ongoing since at least June 2026 and shares similarities with the previously documented FrostArmada campaign, which was linked to APT28, also referred to as Forest Blizzard and Fancy Bear, a state-sponsored group.
