detour_dog
Detour Dog is a cybercriminal threat actor tracked by Infoblox, with activity traces dating back to February 2020 and active tracking since August 2023. The group has compromised tens of thousands of websites globally, including vulnerable WordPress sites, and uses DNS-based malware techniques centered on DNS TXT records for covert command-and-control, traffic redirection, and payload delivery. Their attacks operate server-side, so infected sites usually appear normal to visitors, which supports long-term persistence; reporting states compromised sites can remain infected for over a year. Infoblox reported that infected sites function normally about 90% of the time, redirect visitors to scams about 9% of the time, and receive remote file execution commands about 1% of the time, likely to reduce detection. Detour Dog is associated with infrastructure used to host StarFish, described as a simple reverse shell/backdoor that serves as a conduit for Strela Stealer. Infoblox assessed that the actor controls domains hosting the first-stage component and that at least 69% of confirmed StarFish staging hosts were under Detour Dog control. In June and July 2025, the group was observed evolving from primarily traffic redirection and scam monetization to malware distribution, specifically facilitating Strela Stealer delivery via DNS TXT records. TXT responses were reported as Base64-encoded and included the word "down" to trigger infected sites to retrieve content from Strela Stealer C2 infrastructure. Infoblox stated this was the first time the actor had been observed distributing malware rather than only forwarding traffic. The actor’s operations use compromised websites as relays to obscure hosting and complicate analysis. Infoblox reported that Detour Dog-controlled DNS name servers were modified to parse specially formatted DNS queries and respond with remote code execution commands. The group has also been linked to traffic distribution and scam redirection activity, including prior forwarding of traffic to Los Pollos under the VexTrio Viper umbrella, as well as use of Help TDS or Monetizer TDS for scam redirects. Detour Dog appears to operate in a service-based cybercriminal ecosystem. Infoblox reported that botnets including REM Proxy and Tofsee were used to distribute spam delivering Strela Stealer, while Detour Dog provided malware delivery infrastructure. Reporting also states that Strela Stealer is operated by Hive0145, with Detour Dog acting as a distributor via StarFish. Infoblox described the arrangement as contracted delivery, with botnets delivering spam and Detour Dog delivering the malware. The group’s infrastructure is described as resilient and able to recover quickly from takedown attempts. Infoblox and the Shadowserver Foundation sinkholed two Detour Dog C2 domains, webdmonitor[.]io and aeroarrows[.]io, on July 30 and August 6, 2025. A brief sinkhole of a C2 domain in August 2025 reportedly revealed about 30,000 infected hosts and spikes of more than 2 million DNS TXT requests per hour. No additional aliases or sub-groups are directly identified in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Detour Dog is known for large-scale compromise of websites to deliver DNS-based malware, including the Strela Stealer infostealer and StarFish backdoor, using covert DNS TXT records for C2 and payload delivery.
Detour Dog is a persistent cybercriminal group operating a distribution-as-a-service (DaaS) platform, using compromised WordPress sites to deliver malware and scams.
Operates infrastructure and DNS-based command-and-control/traffic distribution used to stage and distribute Strela Stealer via a first-stage backdoor (StarFish). Compromises vulnerable WordPress sites to inject malicious JavaScript and uses DNS TXT records to relay commands/URLs, enabling remote code execution and multi-stage malware delivery. Assessed to function as a distribution-as-a-service provider and previously focused on traffic-forwarding/scam redirections.
Detour Dog is a cybercriminal group known for infecting websites globally since 2020, initially conducting affiliate scams and later shifting to distributing information-stealing malware (Strela Stealer) via DNS hijacking and covert website infections.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.