Intelligence
highCampaignActive

APT29 targets hospitality Wi-Fi with custom malware to harvest Microsoft 365 credentials

Russian state-sponsored group Midnight Blizzard (APT29) is conducting a global campaign against hotel Wi-Fi networks using custom malware to intercept and steal Microsoft 365 account credentials from business travellers. Hotels represent a soft target with weak network controls and high concentrations of corporate users.

S
Sebastion

Affected

Microsoft 365Hotel Wi-Fi networksBusiness travellers

Microsoft has attributed a global campaign targeting hospitality Wi-Fi networks to Midnight Blizzard, the Russian state-sponsored group also known as APT29. The campaign deploys custom malware designed to intercept and exfiltrate Microsoft 365 credentials from guests connected to hotel networks. This represents a deliberate shift in targeting methodology by a sophisticated adversary: rather than pursuing direct compromise of corporate infrastructure, APT29 is exploiting the asymmetry between traveller device security and hotel network hygiene.

Hotel Wi-Fi networks present an exceptionally attractive attack surface for state-sponsored operators. Most hospitality establishments lack the network monitoring, segmentation, and threat detection capabilities of enterprise environments. Guest networks are typically flat, unencrypted, and accessible without meaningful authentication barriers. Business travellers commonly connect personal and corporate devices without VPN protection, and hotel staff have neither the expertise nor incentive to detect malware distribution or credential interception. A single hotel Wi-Fi deployment can yield credentials from dozens of high-value targets across multiple organisations and geographies in a single week.

The use of custom malware rather than commodity tools suggests APT29 has tailored this campaign for operational security and evasion. Custom code is harder for defenders to detect via signature matching and reduces the risk of exposure through malware analysis platforms. The targeting of Microsoft 365 is strategically sound: cloud identity compromise grants persistent access to email, file storage, and integrated enterprise applications without requiring network persistence or administrative rights on target machines.

Organisations must assume that any employee who has connected a corporate device to a hotel Wi-Fi network in the past 12 months may have had credentials harvested. Defenders should mandate VPN usage for all remote connectivity, enforce multi-factor authentication on all Microsoft 365 accounts with conditional access policies tuned for impossible travel and anomalous sign-in patterns, and conduct forensic review of Microsoft 365 logs for accounts showing suspicious activity correlated with hotel network connections. Hotels themselves require guidance on network segregation, TLS inspection, and detection of malware distribution patterns within their guest networks. The campaign's persistence and sophistication indicate APT29 views this vector as operationally valuable and unlikely to abandon it without encountering meaningful friction.