
APT28 Exploits Hotel Wi-Fi to Hijack Microsoft 365 Accounts via Phishing
Attackers compromised hotel Wi-Fi gateways to redirect business travelers to fraudulent Microsoft 365 login pages, enabling the theft of credentials and authorization tokens. The campaign has been attributed to the threat group APT28, also known as Fancy Bear or Forest Blizzard, which is linked to Russian state-sponsored activities. The attack specifically targets individuals accessing corporate accounts via hotel networks, though no specific hotels, dates, or technical vulnerabilities (e.g., CVE IDs) were disclosed. The impact includes unauthorized access to Microsoft 365 accounts, potentially leading to data breaches or further exploitation. No additional technical details, such as malware names or infection vectors, were provided in the report.