Insights ·

Russian APT targeting public Wi-Fi networks

By Nanorisk

Russian APT targeting public Wi-Fi networks

Midnight Blizzard, the Russian state-sponsored threat group previously linked to the SolarWinds compromise, has been operating a credential theft campaign via compromised Wi-Fi gateways at hospitality organisations. The method is straightforward: gain access to the gateway infrastructure, intercept traffic from connected users, and extract Microsoft account credentials.

What makes this worth paying attention to isn't the sophistication - it's the ordinariness of the attack surface. Hotel Wi-Fi is something travelling employees use without a second thought, often on corporate devices, often while accessing internal systems or email.

The practical takeaway is simple: if your organisation doesn't enforce VPN use on untrusted networks, or hasn't considered how device policy applies when staff are off-site, this is a direct illustration of why that matters. Credential theft at the network layer doesn't require the attacker to touch your infrastructure at all.

Worth reviewing your remote access and device policy if you haven't recently.

Concerned this affects you?

We can assess your exposure and tell you plainly where you stand.

← All insights