Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Future-Proof Your Defense: The Need for Long-Term Planning in Physical AI Security

June 13, 2026

Transform Specs into Agent Evals with ASSERT

June 12, 2026

FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost

June 12, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » Detour Dog Runs DNS Malware Factory for Strela Stealer
Cyber Updates

Detour Dog Runs DNS Malware Factory for Strela Stealer

Staff WriterBy Staff WriterOctober 3, 2025Updated:October 25, 2025No Comments2 Mins Read6 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Quick Takeaways

  1. Detour Dog Unmasked: A threat actor, Detour Dog, has been identified as the source behind campaigns distributing the Strela Stealer information-stealing malware, utilizing compromised websites for attacks.

  2. Innovative Malware Distribution: The malware employs a novel DNS-based strategy, utilizing TXT records to execute remote commands and distribute payloads, marking an evolution in their methods since 2020.

  3. Financial Motivation & Infrastructure: Detour Dog has shifted from forwarding traffic for scams to distributing malware for financial gain, controlling approximately 69% of the identified staging hosts and leveraging botnets for spam email distribution.

  4. Threat Intelligence Efforts: Infoblox worked with the Shadowserver Foundation to sinkhole two of Detour Dog’s command-and-control domains, showcasing ongoing efforts to combat this emerging cybersecurity threat.

Detour Dog’s Intricate Malware Operation

Recently, cybersecurity experts identified a threat actor, known as Detour Dog, behind a sophisticated campaign distributing Strela Stealer, an information stealer. Findings from Infoblox reveal that Detour Dog controls domains hosting the malware’s initial stage, utilizing a backdoor called StarFish. Notably, this group has exploited vulnerable WordPress sites, injecting malicious JavaScript that employs DNS TXT records. This method acts as a traffic distribution system, redirecting visitors to malicious sites and malware.

Furthermore, the malware has evolved. Traditionally, these redirects only facilitated scams. Currently, they enable remote content execution through a DNS-based command-and-control system. Infoblox traces Detour Dog’s activities back to February 2020, indicating a prolonged presence in the cyber threat landscape. The challenge of detection arises, as the compromised websites operate normally most of the time, only raising alarms sporadically.

Evolving Tactics and Malicious Infrastructure

Detour Dog’s infrastructure primarily hosts the StarFish backdoor, which serves as a conduit for Strela Stealer. This backdoor reaches infected machines via malicious SVG files, allowing persistent access. The cybercriminal group operates as an initial access broker, acquiring and selling access to compromised systems.

Recent investigations highlight the sophisticated mechanics behind this operation. Detour Dog uses compromised WordPress sites to execute code remotely, thus enhancing its resilience against detection. Although the primary operations focus on delivering malware, they adapt to shifting security measures to maximize their profits. With the evolution of their tactics, Detour Dog not only poses a significant threat to individual users but also challenges cybersecurity professionals trying to combat such agile and deceptive methodologies.

Expand Your Tech Knowledge

Dive deeper into the world of Cryptocurrency and its impact on global finance.

Access comprehensive resources on technology by visiting Wikipedia.

DataProtection-V1

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAlert: New Threat Group Hijacks IIS Servers for SEO Fraud
Next Article Scattered LAPSUS$ Hunters Reveal Salesforce Breach on New Onion Site
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Future-Proof Your Defense: The Need for Long-Term Planning in Physical AI Security

June 13, 2026

Enterprise AI: Why Data Governance Is Now Critical for Cortex AI

June 12, 2026

Coralogix’s $200M Round Sparks New Observability Era

June 11, 2026

Comments are closed.

Latest Posts

FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost

June 12, 2026

Malicious NPM Campaign Steals SSH Keys, API Tokens, Cloud Credentials & Wallet Secrets

June 12, 2026

Conti Ransomware Member Faces 20 Years After Guilty Plea

June 12, 2026

Fancy Bear Exploits EdgeRouters and Cloud Services for Stealth Cyberattacks

June 12, 2026
Don't Miss

Future-Proof Your Defense: The Need for Long-Term Planning in Physical AI Security

By Staff WriterJune 13, 2026

Summary Points Security architecture should be established early, using hardware roots of trust to prevent…

Enterprise AI: Why Data Governance Is Now Critical for Cortex AI

June 12, 2026

Coralogix’s $200M Round Sparks New Observability Era

June 11, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Future-Proof Your Defense: The Need for Long-Term Planning in Physical AI Security
  • Transform Specs into Agent Evals with ASSERT
  • FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost
  • Malicious NPM Campaign Steals SSH Keys, API Tokens, Cloud Credentials & Wallet Secrets
  • Conti Ransomware Member Faces 20 Years After Guilty Plea
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Future-Proof Your Defense: The Need for Long-Term Planning in Physical AI Security

June 13, 2026

Transform Specs into Agent Evals with ASSERT

June 12, 2026

FBI Cracks Massive China-Based Cybercrime Ring, $1.9B Lost

June 12, 2026
Most Popular

Protecting MCP Security: Defeating Prompt Injection & Tool Poisoning

January 30, 202633 Views

Unlock the Power of Free WormGPT: Harnessing DeepSeek, Gemini, and Kimi-K2 AI Models

November 27, 202530 Views

The New Face of DDoS is Impacted by AI

August 4, 202528 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.