Hackers Hijack Hotel Wi-Fi DNS Settings to Steal Microsoft 365 Credentials
- CVE ID
- N/A
- Affected Products / Orgs
- Hospitality Wi-Fi Routers, Hotel Network Infrastructure, Microsoft 365 Users
Travelers connecting to hospitality networks face a renewed threat as attackers compromise router configurations to execute hotel Wi-Fi DNS hijacking attacks. By altering domain name system settings on public access points and conference center networks, adversaries are silently redirecting legitimate traffic intended for Microsoft 365 login portals to credential-harvesting phishing sites.
Mechanics of the Hospitality Network Attack
Adversaries gain administrative control over hotel and conference venue Wi-Fi routers through unpatched vulnerabilities, exposed management interfaces, or weak default credentials. Once inside the administration interface, attackers modify the network’s local DNS server settings.
When connected guest devices attempt to resolve standard corporate domains—such as login.microsoftonline.com—the compromised DNS server responds with an IP address controlled by the attackers rather than Microsoft’s authoritative name servers. Because the manipulation occurs at the network layer before traffic leaves the access point, browser auto-fill tools and standard domain checks may fail to alert the user that they are navigating to a malicious target.
Risks to Enterprise Credentials
Hotel networks have long been targeted by cyberespionage groups and cybercriminals due to the concentration of corporate executives, remote workers, and high-value enterprise devices. By focusing on Microsoft 365 credential theft, attackers aim to gain persistent access to enterprise email, SharePoint repositories, and cloud resources.
If the phishing infrastructure utilizes Adversary-in-the-Middle (AiTM) reverse proxy frameworks, the attackers can capture primary credentials as well as active session cookies and multi-factor authentication (MFA) tokens in real time. This allows threat actors to bypass standard SMS or authenticator-app MFA prompts and immediately establish an authenticated session on corporate cloud tenants.
Defending Travelers on Public Networks
Organizations must assume that public Wi-Fi infrastructure is inherently untrusted and potentially compromised. Effective mitigation relies on enforcing secure connection protocols that bypass local network DNS settings:
- Enforce Always-On Corporate VPNs: Configure enterprise endpoints to automatically route all internet traffic through an encrypted VPN tunnel that relies on trusted, internal DNS resolvers rather than local gateway settings.
- Deploy Secure DNS Over HTTPS (DoH): Enable DNS over HTTPS or DNS over TLS (DoT) at the operating system or browser level to prevent local network gateways from tampering with name resolution requests.
- Require FIDO2 / WebAuthn MFA: Shift authentication policies away from legacy TOTP or push notifications toward hardware security keys or passkeys. FIDO2 protocols bind authentication to the actual origin domain presented in the browser, preventing user authentication on spoofed domains even if DNS points to an attacker IP.
- Harden Hospitality Gateways: Venue operators and hospitality IT teams must change default router credentials, disable public management interfaces, isolate guest VLANs, and regularly apply firmware updates to prevent router compromise.
Related content
Crafted SVGs in Bing Image Search Allow SYSTEM Command Execution
Security News'Certighost' Flaw in Active Directory Certificate Services Enables Domain Compromise
Security NewsCertighost PoC Released: AD CS Vulnerability Allows Full Windows Domain Hijack
Security NewsCISA and ACSC Release OT Isolation Guidance for Critical Infrastructure
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call