Detour Dog, a persistent cybercriminal group, has been orchestrating a large-scale campaign that leverages DNS hijacking to infect tens of thousands of websites globally. Since at least August 2023, researchers have tracked Detour Dog's operations, which involve compromising website servers and manipulating DNS TXT records to covertly control malicious activity. The group’s infrastructure is highly sophisticated, with compromised servers receiving millions of secret DNS requests per hour at peak times. The attack is particularly insidious because it is executed server-side, making it invisible to most website visitors and allowing infections to persist for over a year. Only a small percentage of visitors are targeted for malicious redirects or malware delivery, with the majority experiencing normal website behavior. Initially, Detour Dog used this infrastructure to redirect users to scams, but in June and July 2025, the group escalated its tactics to deliver the Strela Stealer information-stealing malware. This shift was confirmed by both internal and external researchers, who observed Detour Dog-controlled infrastructure hosting the StarFish backdoor, which was used to install Strela Stealer. The campaign targeted users in Germany and was distributed through malicious email attachments, with Detour Dog’s compromised sites serving as staging points for the malware. The attack chain also involved other botnets, such as REM Proxy and Tofsee, which were used to deliver spam and facilitate the spread of Strela Stealer. Detour Dog’s use of DNS TXT records for command-and-control allowed them to issue conditional instructions to compromised websites, such as redirecting visitors based on their location or device type, or executing remote malicious content. Researchers estimate that at least 69 percent of StarFish staging hosts were under Detour Dog’s control, suggesting the group’s infrastructure is central to the campaign. The DNS-based C2 system enabled Detour Dog to remain stealthy and flexible, adapting their tactics to maximize infection rates while minimizing detection. The campaign’s scale and technical sophistication highlight the evolving threat posed by DNS hijacking and the need for organizations to monitor DNS activity closely. The use of server-side DNS manipulation means traditional endpoint security solutions may not detect the compromise, increasing the risk for both website operators and end users. The campaign demonstrates the growing trend of leveraging infrastructure-level attacks to distribute advanced malware like Strela Stealer, which is operated by the threat actor Hive0145. The collaboration between multiple threat actors and botnets in this campaign underscores the complexity of the modern cybercrime ecosystem. Organizations are advised to review their DNS configurations, monitor for unusual TXT record activity, and ensure their web servers are secured against unauthorized access to mitigate the risk of similar attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Infoblox published research attributing the DNS-based malware delivery infrastructure behind Strela Stealer campaigns to Detour Dog. The report detailed the use of first-stage StarFish backdoors, compromised websites as relays, and DNS-triggered payload retrieval from Strela command-and-control systems.
Infoblox disclosed that over 30,000 compromised websites were involved in the Detour Dog infrastructure supporting Strela Stealer delivery. Most affected sites appeared normal to typical visitors, helping the campaign remain hidden at scale.
Infoblox found that Detour Dog used DNS TXT records carrying Base64-encoded commands to control infected websites and relay payload delivery, with some infections persisting for more than a year. The infrastructure generated millions of covert DNS requests per hour while only selectively serving malicious content to a small subset of visitors.
Researchers assessed that Detour Dog expanded from redirection and scam activity into a service-based malware distribution operation, supporting Strela Stealer campaigns for other actors such as Hive0145. The operation used compromised WordPress sites, staging domains, and botnet-driven spam delivery via REM Proxy and Tofsee.
In late July and early August 2025, Infoblox and the Shadowserver Foundation sinkholed two command-and-control domains associated with Detour Dog. The action disrupted part of the DNS-based infrastructure used in the Strela Stealer delivery chain.
Infoblox reported that the threat actor it tracks as Detour Dog has been compromising websites worldwide since 2020. The group initially appears to have focused on traffic redirection and scam monetization before later shifting toward malware delivery.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourcehackread.com
Open sourceblogs.infoblox.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.