highAPT

Midnight Blizzard Hotel Wi-Fi Campaign Targeting Microsoft 365 Accounts

First seen Aug 4, 2026 · Updated Aug 4, 2026

APT29Midnight BlizzardhospitalityWi-FiMicrosoft 365credential-theftRussianation-stateagent-relevant

Microsoft has attributed a global campaign against hospitality Wi-Fi networks to the Russian state-sponsored actor Midnight Blizzard (APT29). The group uses custom malware deployed via compromised hotel networks to intercept traffic and steal Microsoft 365 credentials from traveling targets, likely diplomats, government officials, and corporate executives. The campaign highlights the ongoing risk of adversary-in-the-middle attacks on untrusted public networks.

Technical Analysis

The campaign leverages access to hospitality Wi-Fi infrastructure to position Midnight Blizzard operators as adversary-in-the-middle, enabling deployment of custom malware to victim devices connecting to compromised networks. The malware is used to harvest Microsoft 365 authentication material, including session tokens and credentials, facilitating persistent access to cloud email and collaboration data without triggering standard MFA in some cases via token theft. Given Midnight Blizzard's historical tradecraft, techniques likely include forged authentication tokens, OAuth consent abuse, and living-off-the-land binaries to evade detection post-compromise. Organizations whose personnel travel and connect AI agent orchestration tools, RAG pipelines, or Copilot/M365 integrations to hotel networks risk having stolen Microsoft 365 credentials or tokens reused to access connected agent frameworks, exposing API keys, SharePoint/OneDrive data sources, and automated workflows tied to the compromised account. This makes the campaign directly relevant to enterprises running AI agents integrated with Microsoft 365 identity and data services.

Affected Systems

Microsoft 365 accounts and associated OAuth/session tokens; devices connecting to hospitality/hotel Wi-Fi networks; Windows and mobile endpoints used by traveling employees; any AI agent or automation tooling integrated with Microsoft 365 identity (e.g., Copilot, Graph API-connected agents)

Indicators of Compromise

  • Not disclosed in available reporting

Remediation Steps

  1. 1

    Enforce phishing-resistant MFA

    Require FIDO2/hardware security keys for Microsoft 365 accounts, especially for executives and staff who travel frequently.

  2. 2

    Restrict use of public/hotel Wi-Fi

    Mandate use of corporate VPN or cellular hotspots instead of hotel Wi-Fi for accessing Microsoft 365 and connected agent systems.

  3. 3

    Monitor for anomalous token usage

    Enable Conditional Access policies and monitor sign-in logs for impossible travel, new device, or token replay anomalies.

  4. 4

    Rotate and audit tokens/API keys

    Revoke and rotate OAuth tokens, session cookies, and API keys used by AI agents or automation tools linked to potentially compromised Microsoft 365 accounts.

  5. 5

    Deploy endpoint detection

    Ensure EDR coverage on traveling employee devices to detect custom malware associated with Midnight Blizzard tradecraft.

Industries Most Exposed

hospitalitygovernmentdiplomaticcorporate enterprisetravel

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.