Hackers Hit Hotel Wi-Fi With Custom Malware to Steal Microsoft Logins

By 813 Staff

Hackers Hit Hotel Wi-Fi With Custom Malware to Steal Microsoft Logins

Breaking from the tech world: Hackers Hit Hotel Wi-Fi With Custom Malware to Steal Microsoft Logins, according to BleepingComputer (@BleepinComputer) (in the last 24 hours).

Source: https://x.com/BleepinComputer/status/2084433509418983475

The first sign of trouble was the login prompt. A sales executive, three days into a conference at a luxury hotel in Singapore, watched his laptop request Microsoft 365 credentials for the second time that morning. He typed his password, sighed at the two-factor authentication buzz on his phone, and approved it. He never thought to ask why the hotel Wi-Fi was asking him to re-authenticate his corporate account at all. That session, according to forensic analysis shared with @BleepinComputer and first reported on August 4, became the entry point for a campaign that has been quietly gutting corporate inboxes across the Asia-Pacific region for the last six weeks.

The attack vector is deceptively simple. Internal documents show the threat actors are not exploiting zero-days in Microsoft's cloud. Instead, they've built custom malware designed specifically to intercept authentication tokens as they traverse compromised hotel networks. Engineers close to the project say the malware sits on the local network, waits for a victim to connect, and then injects a fake browser extension or performs an adversary-in-the-middle attack that harvests the session cookies tied to Microsoft 365. Once those cookies are grabbed, the attackers can bypass MFA entirely — because they're not bypassing anything. They're using the legitimate session that your phone just approved.

The rollout has been anything but smooth for the defenders. The malware, which researchers have tentatively named “LobbyJack,” has been observed in at least eleven properties across Singapore, Hong Kong, and Bangkok, with suspected activity in Dubai. It is not a spray-and-pray operation. The attackers are targeting specific business travelers — sales teams, legal counsel, and finance executives — and they wait until the mark has left the building before exfiltrating mailboxes. The looting is surgical: password resets, financial documents, and MFA backup codes are grabbed first.

The timing is brutal. This is August, the peak of global conference season, and most corporate cybersecurity teams are stretched thin. What remains uncertain is whether this is a single group or a platform-as-a-service offering sold on underground forums. Sources say Microsoft has issued an advisory to enterprise tenants, but the company has not publicly confirmed the scope.

For now, the advice from incident responders is painfully retro: do not use hotel Wi-Fi for work. Tether to your phone, or carry a dedicated roaming hotspot. The new frontier of corporate espionage isn't a phishing email. It’s the complimentary breakfast bar and the lobby’s “premium” bandwidth.

Source: https://x.com/BleepinComputer/status/2084433509418983475

Related Stories

More Technology →