threat-intel
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
High
Summary
A Russian state-sponsored APT group, Storm-2945 (linked to Midnight Blizzard/APT29), is leveraging compromised public Wi-Fi gateway networks to steal Microsoft 365 credentials of traveling employees. The campaign involves manipulating DNS and HTTP traffic, serving Golang-based RATs, and utilizing device code phishing techniques to gain access to corporate networks, primarily targeting sectors like finance, legal, healthcare, and retail.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data