← Back to Tech & Science

Russian Hackers Target Global Hospitality Wi-Fi in Microsoft 365 Campaign

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

LONDON — Russian threat actor Midnight Blizzard, also known as APT29 and Storm-2945, launched a global campaign targeting hospitality Wi-Fi networks to compromise Microsoft 365 accounts. The operation utilized custom malware and Domain Name System (DNS) manipulation to breach corporate credentials across the hotel industry.

Microsoft identified the attack on Aug. 4, 2026, linking the intrusion to the Russian state-sponsored group known for its sophisticated cyberespionage activities. The campaign specifically focused on Wi-Fi networks at hotels and conference centers worldwide, exploiting unsecured guest connections as an entry point into corporate environments. Attackers deployed custom malware designed to intercept user sessions once devices connected to compromised wireless infrastructure.

The primary objective of the operation was the theft of Microsoft 365 accounts, including administrative credentials, session tokens, and sensitive data stored within cloud-based productivity suites. By manipulating DNS records, the threat actors redirected traffic from legitimate login portals to fraudulent phishing pages that mimicked official Microsoft interfaces. This technique allowed them to harvest valid authentication details without triggering standard security alerts.

Once inside the networks, the malware facilitated the exfiltration of proprietary information and provided persistent access for further reconnaissance. The breach mechanism relied heavily on the high volume of transient devices connecting to hospitality Wi-Fi, which often lack the rigorous endpoint protections found in corporate office environments. Travelers and conference attendees unknowingly became vectors for the intrusion as their laptops connected to infected networks.

The attack highlights a shifting strategy by state-sponsored groups toward targeting peripheral network access points rather than direct server exploitation. By focusing on guest-facing infrastructure, Midnight Blizzard bypassed traditional perimeter defenses that are typically concentrated around core business systems. The group's use of custom malware indicates a tailored approach designed to evade detection by standard antivirus software.

Security experts noted the sophistication of the DNS manipulation techniques used in this campaign, which allowed attackers to maintain control over traffic redirection even after initial infection vectors were identified. The scope of the operation remains under assessment as organizations globally scan their networks for signs of compromise and reset compromised credentials.

Questions remain regarding the full extent of data exfiltration and whether specific government or corporate entities within the hospitality sector suffered significant losses. Microsoft is working with affected partners to deploy patches and update security protocols, but the transient nature of hotel Wi-Fi usage complicates long-term remediation efforts. As investigations continue, cybersecurity firms are monitoring for variations of this campaign that could target other industries relying on public wireless access.

Discussion

0 / 2000