Cybersecurity researchers at ReliaQuest have identified an active DNS poisoning campaign targeting Wi-Fi infrastructure at hotels, conference centers, and other hospitality venues frequented by corporate employees. The attackers compromise routers providing public Wi-Fi access to silently intercept and harvest login credentials from business travelers. Affected locations span multiple US cities, India, and Saudi Arabia, with the campaign showing tradecraft similar to APT28, a cyber espionage group linked to Russian military intelligence.
The attack begins when threat actors gain initial access to Wi-Fi routers by exploiting exposed management interfaces including SSH, SNMP, and web administration consoles. In many cases, attackers leverage weak or reused administrator credentials to breach these devices. Once inside, they modify router configurations to implement DNS poisoning, which redirects traffic for legitimate domains through attacker-controlled servers.
This technique allows credential theft without requiring phishing emails, malicious attachments, or direct device compromise. Victims connect to what appears to be normal Wi-Fi service and browse websites as usual, unaware that their traffic routes through hostile infrastructure. The attackers can monitor all activity and capture usernames, passwords, and other sensitive information as users authenticate to corporate systems and web services. Because the DNS manipulation happens at the network level, users see no visible indicators of compromise.
The campaign specifically targets venues where corporate employees gather, creating opportunities to harvest credentials that provide access to sensitive business systems and data. ReliaQuest researchers warn that any organization operating captive portal networks faces similar risks, including airports, co-working spaces, universities, healthcare facilities, and event venues. The ongoing nature of the campaign suggests a sustained effort to collect corporate access credentials at scale.
Organizations can defend against these attacks through several measures. ReliaQuest recommends enforcing always-on VPN connections with full-tunnel configuration to route all DNS requests through trusted corporate resolvers. Security teams should audit proxy authentication logs for connections from unknown hosts and suspicious activity from known abused infrastructure. Additional protections include disabling web proxy auto-discovery where not needed, training employees to verify URLs and certificates before entering credentials on public networks, and blocking device-code authentication flows through conditional access policies in identity providers like Microsoft Entra ID.
Source: https://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/


