Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

StarFish

StarFish is a simple reverse shell/backdoor used in DNS-orchestrated malware campaigns as the first-stage component and conduit for Strela Stealer. Reporting attributes the infrastructure hosting and delivery of StarFish to the threat actor Detour Dog, which has used compromised WordPress sites, malicious JavaScript, and DNS TXT records for covert command-and-control and payload delivery. Infoblox assessed that Detour Dog controls domains hosting StarFish and that at least 69% of confirmed StarFish staging hosts were under Detour Dog control. IBM X-Force reported in July 2025 that StarFish was delivered via malicious SVG files to enable persistent access to infected machines. The broader attack chain has also involved spam delivery through the REM Proxy and Tofsee botnets, with Detour Dog acting as a service provider/partner to distribute malware for Strela Stealer operations associated with Hive0145. Observed behavior includes DNS TXT responses that are Base64-encoded and include the word "down" to trigger infected sites to retrieve content from Strela Stealer C2 infrastructure, using compromised websites as relays to obscure hosting and complicate analysis. Related infrastructure included sinkholed Detour Dog C2 domains webdmonitor[.]io and aeroarrows[.]io in July and August 2025.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
detour_dog

Detour Dog-owned infrastructure, per the company, has been used to host StarFish, a simple reverse shell that serves as a conduit for Strela Stealer.

via the hacker newsthehackernews.com
INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
2 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app9 months ago
domain●●●●●●●●●●●●View more in app9 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.