Midnight Blizzard Targets Hotel Wi-Fi to Breach Microsoft 365 Accounts

Microsoft has linked a widespread campaign that targets hotel Wi-Fi networks worldwide to the Russian advanced persistent threat actor Midnight Blizzard, also known as APT29. This operation employs custom-designed malware to compromise Microsoft 365 accounts by exploiting connectivity within hospitality environments.
What happened
Microsoft has uncovered a global espionage campaign led by the Russian threat group Midnight Blizzard (APT29), focusing on hospitality Wi-Fi networks. The attackers deployed custom malware that enables them to infiltrate Microsoft 365 accounts of hotel guests and staff. By compromising unsecured or poorly secured Wi-Fi infrastructure in hotels, the threat actor gains a foothold to collect credentials and access sensitive cloud-based services.
Why it matters
The targeting of hospitality Wi-Fi networks marks a significant shift as attackers exploit public and semi-public network environments to reach valuable corporate and individual cloud accounts. Microsoft 365 is widely used for business communications and collaboration, making breaches into these accounts particularly concerning. The campaign underlines the risks posed by Wi-Fi networks in sectors that may not traditionally prioritize robust cybersecurity defenses.
What security teams should do
Organizations, especially within the hospitality sector, should review the security posture of their Wi-Fi networks to prevent unauthorized access. Users should be cautious when connecting to hotel Wi-Fi networks and consider using VPN services. Additionally, security teams should monitor for indicators of compromise related to Midnight Blizzard activity and ensure multi-factor authentication (MFA) is enforced for Microsoft 365 accounts to limit the impact of credential theft.
Key technical details
The campaign uses custom malware designed specifically for the hotel Wi-Fi environment to capture credentials and enable access to Microsoft 365 cloud services. Attackers exploit the trust users place in hotel Wi-Fi to intercept authentication tokens or passwords. The malware operates by establishing control over network traffic within the compromised Wi-Fi network, facilitating stealthy exfiltration of credentials and lateral movement within the targeted Microsoft 365 tenant.
Affected organizations/products
The campaign targets hospitality networks globally, potentially affecting hotel guests and employees who access Microsoft 365 accounts via hotel Wi-Fi. Specific organizations or regions affected were not disclosed by Microsoft.