logo

Detour Dog: DNS Malware Powers Strela Stealer Campaigns

ID: 087625e8-ea12-53fd-97b0-634b644047f4

STIX ID: report--087625e8-ea12-53fd-97b0-634b644047f4

Feed Name: Infoblox Threat Intel Blog

Threat Score
80/100

Date Published: 2025-09-30

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Detour Dog operates a large, resilient DNS-based website malware system that issues Base64-encoded DNS TXT responses (including a "down" command) to compromised sites, enabling server-side redirects and remote execution to fetch staged payloads; the infrastructure has been used to distribute the StarFish backdoor and Strela Stealer, with sinkhole data revealing ~30,000 infected hosts across 584 TLDs and millions of TXT queries, demonstrating a novel, high-volume malware distribution and evasion technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.