#5
BleepingComputer
general
August 04, 2026 at 00:17 UTC
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
By Bill Toulas
AI Summary
Microsoft has attributed a global campaign targeting hotel and hospitality Wi-Fi networks to Midnight Blizzard (APT29), Russia's SVR-linked threat actor, which used custom malware to steal Microsoft 365 credentials from guests connecting through compromised gateways. The attackers deployed purpose-built implants to intercept authentication traffic, extending APT29's well-documented interest in credential harvesting against high-value travelers. Security teams managing hospitality environments or advising traveling executives should treat guest Wi-Fi infrastructure as a high-risk attack surface.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →