Technology

DNS Poisoning Campaign Makes Hospitality Wi-Fi Spots Inhospitable

Rather than targeting individual devices, attackers are compromising hospitality Wi-Fi gateways to steal corporate credentials at far greater scale. The post DNS Poisoning Campaign Makes Hospitality Wi-Fi Spots Inhospitable appeared...

AAdmin
July 29, 2026
3 min read
DNS Poisoning Campaign Makes Hospitality Wi-Fi Spots Inhospitable

In what appears to be a state-sponsored credential theft campaign, a group of network marauders has been targeting Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack corporate travelers' accounts.

Once the threat actors control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, according to a report by ReliaQuest, a global security operations and threat response automation company.

According to ReliaQuest, the activity has been ongoing since at least June 2026.

The compromised devices investigated by ReliaQuest were appliances primarily used at hotels and other organizations running captive Wi-Fi services, explained the report authored by researchers Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie and Connor Short.

The researchers said, with "low-to-medium confidence," that the attackers likely gained initial access through exposed management interfaces combined with weak or reused administrative credentials, although limited visibility into the compromised devices prevented them from confirming that assessment.

That methodology would be consistent with the gateway targeting and DNS poisoning patterns documented in recent reporting on an APT28-linked campaign known as "FrostArmada," the report noted.

FrostArmada, a cyberespionage campaign linked to the Russian threat group Forest Blizzard, also known as APT28 and Fancy Bear, hijacked DNS settings on compromised routers to redirect authentication traffic and steal Microsoft credentials and OAuth tokens. It was disrupted in April 2026 through a joint operation involving law enforcement and private-sector partners.

The report explained that once the attacker compromised the gateway devices, they modified their configurations and used DNS poisoning to redirect regular web traffic, funneling connections for legitimate domains through attacker-controlled infrastructure.

"Hotels and conference centers are not random targets," observed James Edwards, senior director of engineering at Keeper Security , a password management and online storage company in Chicago.

"These are environments where senior executives, legal teams, financial professionals and other high-value corporate employees routinely connect to shared Wi-Fi without thinking twice about it," he told TechNewsWorld.

"A single compromised gateway at a major industry conference gives an attacker access to hundreds — or even thousands — of corporate devices from a range of organizations," he explained. "The infrastructure economics are extraordinary."

"What makes this campaign particularly dangerous is that it operates entirely below the user's awareness," he continued. "When an attacker owns the gateway, they don't need to touch a single endpoint, send a single phishing email or plant a single piece of malware."

"DNS poisoning redirects traffic silently," he added. "The user browses normally, enters credentials normally and has no reason to suspect anything is wrong."

These attacks are becoming increasingly common, noted Denis Calderone, principal and CTO of Suzu Labs , a provider of AI-powered cybersecurity services in Las Vegas.

"This is basically the same playbook as what APT28 did with 18,000 home routers in the FrostArmada campaign back in April," he told TechNewsWorld. "In this case, the attacker is targeting legitimate hotel Wi-Fi gateways."

One particularly concerning aspect of the campaign involves device-code authen…