Business and holiday travelling has just become even more risky as hackers believed to be connected to Russian intelligence have discovered a way to hijack wi-fi gateways at hotels and conference centers. This enables them to secretly redirect users to attacker-controlled infrastructure to steal credentials.
According to an advisory from cybersecurity company Reliaquest, this activity has been in train since at least June of this year. Reliaquest believes the techniques used are those associated with the group Fancy Bear, alias Forest Blizzard and APT28 — a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts. The attacks quietly compromise the Microsoft 365 accounts of corporate employees without touching their devices or sending a single phishing email.
Since June, compromised wi-fi gateways have been identified across multiple US cities and in India and Saudi Arabia, primarily in hotel and hospitality organizations. Reliaquest observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail — suggesting that this isn't sector-specific targeting, but a campaign that highly likely goes after travelling employees wherever they connect. Airports, co-working spaces, universities, health care facilities, and event venues are also potentially vulnerable to this type of attack.
Other attack methods include the "Pineapple"
Harvesting the credentials of travelling employees in hotel lobbies and similar locations is not a new threat. Previously existing attack methods include a device known as a "Pineapple." Available online for as little as $150, this device can be carried in a briefcase or under a jacket and enables its owner to replace the local wi-fi network with his or her own connection in order to spy on the online activities of users. But Fancy Bear's attacks can be conducted on a far bigger scale.
According to Reliaquest: "The significance of this device class is the environment it controls. Captive portal appliances sit at the network perimeter for every guest on that network. A single device compromise gives the attacker control to redirect traffic from every guest logging into the network that day, without touching a single endpoint."
Reliaquest recommends that all corporate devices use an always-on VPN with full-tunnel configuration, ensuring that all domain-name system (DNS) requests route through trusted corporate resolvers, mitigating the attack vector. Alternatively, business travellers might consider tethering their device to the mobile hotspot on their smartphone to avoid logging into potentially compromised wi-fi networks.
