logo

Detour Dog: DNS Malware Powers Strela Stealer Campaigns

ID: 0017ac58-c941-55d7-b228-83a880eb2e03

STIX ID: report--0017ac58-c941-55d7-b228-83a880eb2e03

Feed Name: Infoblox Threat Intel Blog

Threat Score
80/100

Date Published: 2025-09-30

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Detour Dog is a widespread website malware campaign that uses server-side DNS TXT queries as a covert C2 and delivery mechanism to conditionally redirect visitors, execute remote code on compromised sites, and stage infostealer distribution (StarFish/ Strela Stealer). Sinkholing revealed ~30,000 infected hosts across hundreds of TLDs and tens of millions of TXT queries; the infrastructure uses redirector domains, affiliate TDS chains, and evolving TXT responses (including Base64-encoded “down” commands) to fetch and relay staged payloads while evading detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.