FireEye has moderate confidence that a campaign targeting the
hospitality sector is attributed to Russian actor href="https://www.fireeye.com/blog/threat-research/2014/10/apt28-a-window-into-russias-cyber-espionage-operations.html">APT28.
We believe this activity, which dates back to at least July 2017, was
intended to target travelers to hotels throughout Europe and the
Middle East. The actor has used several notable techniques in these
incidents such as sniffing passwords from Wi-Fi traffic, poisoning the
NetBIOS Name Service, and spreading laterally via the href="https://www.fireeye.com/blog/threat-research/2017/05/smb-exploited-wannacry-use-of-eternalblue.html">EternalBlue exploit.