Detour Dog is a financially motivated cybercriminal threat actor associated with large-scale compromise of vulnerable WordPress websites and covert DNS-based traffic manipulation. Activity attributed to the group dates back to at least 2020, with public tracking beginning in 2023. The actor has infected tens of thousands of websites globally and uses server-side malware and DNS TXT record responses as a covert command-and-control and payload delivery channel, allowing compromised sites to appear normal to most visitors while selectively redirecting a small portion of traffic to scams or malware. Detour Dog is notable for operating resilient infrastructure that rapidly recovers from disruption and for using compromised websites as relays to obscure downstream malicious hosting. The group historically monetized access through traffic redirection and scam delivery, including links to malicious traffic distribution ecosystems such as Los Pollos under the VexTrio Viper umbrella. By mid-2025, the actor expanded into malware delivery, using infrastructure that hosted the StarFish backdoor as a first-stage component in campaigns distributing Strela Stealer. StarFish has been described as a simple reverse shell or backdoor that enables follow-on retrieval and execution of additional malicious content. The actor abuses DNS TXT records for covert communications, remote tasking, and staged payload delivery. Detour Dog-controlled name servers have been modified to parse specially formatted DNS queries and return encoded commands that instruct infected sites to redirect visitors or fetch and execute remote content. Confirmed campaigns also relied on spam delivery through botnets including REM Proxy and Tofsee, indicating a service-based criminal ecosystem in which Detour Dog provides malware delivery and staging infrastructure for other actors, including the Strela Stealer operator Hive0145. Observed behavior demonstrates persistence, defense evasion, initial access through exploitation of vulnerable web infrastructure, and post-exploitation control of compromised servers. The actor’s operations are global in scope, but currently available information does not support high-confidence attribution to a specific country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Detour Dog is known for large-scale compromise of websites to deliver DNS-based malware, including the Strela Stealer infostealer and StarFish backdoor, using covert DNS TXT records for C2 and payload delivery.
Detour Dog is a persistent cybercriminal group operating a distribution-as-a-service (DaaS) platform, using compromised WordPress sites to deliver malware and scams.
Operates infrastructure and DNS-based command-and-control/traffic distribution used to stage and distribute Strela Stealer via a first-stage backdoor (StarFish). Compromises vulnerable WordPress sites to inject malicious JavaScript and uses DNS TXT records to relay commands/URLs, enabling remote code execution and multi-stage malware delivery. Assessed to function as a distribution-as-a-service provider and previously focused on traffic-forwarding/scam redirections.
Detour Dog is a cybercriminal group known for infecting websites globally since 2020, initially conducting affiliate scams and later shifting to distributing information-stealing malware (Strela Stealer) via DNS hijacking and covert website infections.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.