The Network Under Your Executive Has Been Turned Against Them
ReliaQuest has identified attackers tampering with DNS settings on hotel and conference-center Wi-Fi gateways, quietly redirecting guests to counterfeit Microsoft 365 login pages. The mechanics matter here because the compromise sits below the user. A traveling CFO opens a laptop in a hotel lobby, types the real Outlook web address, and the poisoned resolver hands back an attacker-controlled destination. Nothing on the endpoint looks wrong. The certificate warnings that once protected users are increasingly absent from these operations, and the average traveler is not inspecting DNS responses between meetings. This is infrastructure-level deception aimed at the moment your most senior people are least defended.
For technology leaders, the uncomfortable part is jurisdiction. You do not own the hotel gateway, you cannot patch the conference-center router, and your traveling staff will connect regardless of policy. ReliaQuest observed some cases also abusing Web Proxy Auto-Discovery, or WPAD, to reroute traffic through attacker-controlled paths. WPAD has been a known liability for years, yet it still ships enabled on many corporate builds. When the network itself lies about where a domain lives, endpoint hygiene and user training only carry you so far. The defensive center of gravity has to move to identity and session controls, because the transport layer is no longer yours to trust.
Device-Code Phishing Turns Consent Into Compromise
The clever part of this campaign is that it does not need your password. It uses a device-code authentication flow, the same mechanism built for signing in TVs and command-line tools that cannot render a browser. The attacker initiates an authentication request, obtains a short code, and presents it to the victim through the fake portal. The victim, believing they are completing a normal login, approves the prompt. As ReliaQuest researchers put it: "What the user can't see is that approving the prompt authorizes a session initiated by the attacker." The result is a fully authenticated token in the attacker's hands, granted willingly by the target.
This is why the technique bypasses multi-factor authentication instead of fighting it. The victim performs MFA legitimately, satisfying every control your identity provider expects, and then hands the resulting session to someone else. There is no cracked hash, no reused credential, no anomalous password spray for your SOC to catch. Device-code phishing exploits a design assumption baked into OAuth: that the person approving a code is the person who requested it. For any organization that has invested heavily in MFA as its primary line of defense, this campaign is a direct message that authentication strength and session integrity are two different problems.
The Domains and the Geography Tell a Coordinated Story
ReliaQuest documented at least four attacker-registered phishing domains: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. The naming is deliberate, blending Microsoft 365, Outlook Web Access, and device-flow language so that a hurried glance reads as legitimate. These are worth loading into your blocklists and email gateways today, but treat them as a sample rather than the full set. Operators who can register and rotate lookalike domains at will treat any single indicator as disposable. The pattern behind the names is the durable signal, and your detection engineering should target the pattern rather than chasing individual strings.
Geographically, compromised gateways surfaced across multiple U.S. cities alongside India and Saudi Arabia, which points to infrastructure staged where high-value travelers concentrate. The targeted sectors reinforce that read: financial services, professional services, legal, healthcare, energy, and retail. These are industries dense with executives who travel to close deals, attend conferences, and log in from unfamiliar networks. The attackers are not spraying consumers. They are positioning at the physical waypoints of corporate decision-makers, which tells you the operation is patient, resourced, and selective about where it plants its listening posts.
Why This Looks Like a Nation-State Playbook
The activity has been ongoing since at least mid-2026, and its tradecraft resembles the FrostArmada router-based campaigns previously attributed to the Russian espionage group APT28, also tracked as Fancy Bear and Forest Blizzard. ReliaQuest was careful here, stopping short of formal attribution, and that restraint is worth respecting rather than reading past. What we can say is that the operational profile fits a state-aligned espionage actor more than a smash-and-grab criminal crew. Manipulating network infrastructure at travel hubs, harvesting sessions from specific sectors, and maintaining persistence across borders is expensive work that pays off in intelligence, not quick fraud.
For a CISO, the attribution question is less useful than the capability question. Whether this is APT28 or a group borrowing its methods, the takeaway is the same: the technique is now in circulation and it works. FrostArmada demonstrated that consumer and edge routers are viable footholds for espionage, and this campaign extends that logic to hospitality networks. Treating it as a Russia problem lets too many teams off the hook. The right framing is that infrastructure-layer identity theft is a mature, repeatable method, and any competent actor with modest resources can now run the same play against your traveling workforce.
Your MFA Investment Just Got a Harder Question to Answer
Most enterprises spent the last several years standardizing on MFA and treating it as the finish line for account security. This campaign reframes that spend. If an attacker can obtain a valid session without ever touching the second factor, then MFA coverage numbers, however impressive, stop being a proxy for safety. The board-level metric you have been reporting measures authentication events, and this attack lives in the gap between authentication and session ownership. We would push leadership to stop treating an MFA rollout as a closed project and start treating session integrity as the next line item that needs budget and engineering attention.
The practical hardening is available and underused. Disable device-code flow where your organization has no legitimate need for it, and scope it tightly where you do. Enforce conditional access that evaluates device compliance and network posture, not just a successful login. Bind sessions to managed devices so a token minted on an attacker's machine fails downstream checks. Kill WPAD on corporate builds. None of these are exotic, and all of them close the specific gap this campaign exploits. The work is unglamorous, but it converts a theoretical control into one that actually holds when the network turns hostile.
What Belongs on the Roadmap This Quarter
Start with the assumption that untrusted networks are the default reality for your executives, because they are. Push traveling staff onto corporate VPN or a secure access service edge tunnel that resolves DNS through infrastructure you control, so a poisoned hotel gateway never gets a vote on where your traffic goes. Load the four observed domains and their pattern into your gateways now, then instrument for device-code grants in your identity logs, which many teams have never bothered to monitor. A sudden device-code approval from a hotel IP range in an unfamiliar city is exactly the signal this attack generates, and it is detectable if you are watching.
Longer term, this is a governance conversation as much as an engineering one. The reader who owns identity strategy should be reevaluating which authentication flows are enabled by default across the Microsoft 365 tenant and whether each one earns its keep against its risk. We have argued before that identity is the real perimeter, and campaigns like this are the proof. The organizations that come through cleanly will be the ones that treated MFA as a foundation to build on rather than a box to check. The gap between those two postures is where the next quarter of security work should go.



