Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click episode artwork

EPISODE · Jul 29, 2026 · 31 MIN

Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click

from ShadowTalk: Powered by ReliaQuest

An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token. Join hosts Alexandra Moore and John Dilgen as they break down:How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft authentication trafficWhy hardcoded DNS, opportunistic encrypted DNS, and MFA may not stop the attackHow device-code phishing and WPAD abuse expand the campaign’s reachPractical defenses—including always-on, full-tunnel VPN, strict-mode encrypted DNS, and Conditional Access controls Two questions your organization should be asking right now:Does your always-on VPN tunnel all DNS and authentication traffic, or do split-tunneling exceptions leave traveling employees exposed?Who is permitted to authenticate through the device-code flow, and does each exception have a legitimate business justification?John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

Episode metadata supplied by the publisher feed · Published Jul 29, 2026

Embed this episode

An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token. Join hosts Alexandra Moore and John Dilgen as they break down: How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft authentication trafficWhy hardcoded DNS, opportunistic encrypted DNS, and MFA may not stop the attack...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click

0:00 31:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of ShadowTalk: Powered by ReliaQuest?

This episode is 31 minutes long.

When was this ShadowTalk: Powered by ReliaQuest episode published?

This episode was published on July 29, 2026.

Can I download this ShadowTalk: Powered by ReliaQuest episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!