A sophisticated malware campaign, known as Detour Dog , is using thousands of compromised websites worldwide to distribute the Strela Stealer malware through an unprecedented technique involving DNS TXT records .
See also: New Botnet Exploits DNS Misconfiguration

The Detour Dog threat, which is being monitored by security researchers, represents a significant evolution in malware distribution methods that exploit the Domain Name System (DNS) both as a command-and-control mechanism and as a distribution channel.
The malware campaign affects tens of thousands of websites worldwide, creating a vast network of infected sockets that communicate with name servers controlled by the attackers via specially crafted DNS queries. These server-side DNS requests remain invisible to website visitors, allowing the malicious infrastructure to operate in secret while maintaining the appearance of legitimate web traffic.
The compromised websites redirect visitors conditionally to malicious content based on their geographic location and device type, creating an advanced filtering mechanism that helps avoid detection. Detour Dog has evolved significantly from its original form as a redirection operation into a fraud scheme.
The attacker behind this campaign has been active since at least August 2023, initially focusing on redirecting users to fraudulent websites and tech support scams. However, recent developments show a clear shift towards direct malware distribution, especially in campaigns targeting European users with the Strela Stealer payload.
Infoblox analysts first identified the connection between Detour Dog’s infrastructure and Strela Stealer operations in the summer of 2025, when they discovered that at least 69% of confirmed StarFish staging hosts were under Detour Dog’s control. This discovery revealed that the attacker was not simply redirecting traffic, but was actively involved in multi-layered malware distribution chains that culminated in information theft operations .
See also: Hackers exploit DNS queries to steal data

The technical complexity of the command and control system of Detour Dog that is based on DNS represents a new approach to malicious software communication that exploits the usually neglected functionality of DNS TXT records. Infected websites generate DNS queries following a structured format that embeds victim information directly into the subdomain structure.
The system underwent a major upgrade in the spring of 2025, when operators added remote code execution capabilities triggered by Base64 containing the keyword “down.” When an infected website receives such a response, it strips the prefix and uses curl to retrieve content from specified URLs, effectively turning compromised websites into proxy servers for distributing malware.
DNS TXT responses follow a specific format that allows for complex multi-layered load distribution. This command instructs the infected website to retrieve content from a StarFish C2 server and transmit it back to the victim, creating a distributed distribution network that hides the true source of the malicious content. The system supports both script.php and file.php endpoints , which correspond to different stages of the Strela Stealer distribution process.
The attacker has demonstrated remarkable resilience in maintaining its infrastructure. When the Shadowserver Foundation took over the webdmonitor.io domain in August 2025, Detour Dog operators established a replacement C2 server within hours, seamlessly transferring control of their network of infected websites to the new aeroarrows.io domain .
See also: Hazy Hawk compromises trusted domains via DNS

Analysis of the data from the sinkhole revealed approximately 30,000 unique domains spanning 584 different top-level domains, all generating well-formed DNS TXT queries to the attacker-controlled infrastructure. The scale and persistence of this operation underscores the effective nature of the Detour Dog campaign.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
