{"id":8353,"date":"2025-10-03T11:11:11","date_gmt":"2025-10-03T15:11:11","guid":{"rendered":"https:\/\/www.landontechnologies.com\/blog\/?p=8353"},"modified":"2026-05-30T07:52:25","modified_gmt":"2026-05-30T11:52:25","slug":"dns-malware-detour-dog","status":"publish","type":"post","link":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/","title":{"rendered":"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A newly reported campaign nicknamed <strong>\u201cDetour Dog\u201d<\/strong> quietly compromised more than <strong>30,000 websites<\/strong> by abusing Domain Name System (DNS) logic to redirect visitors and deliver malware, including the <em>Strela<\/em> info-stealer. Below we break down what happened, why it matters for small and medium-sized businesses, and the practical steps to protect your organization.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"600\" src=\"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero.webp\" alt=\"DNS security protecting small business websites from Detour Dog hijacks\" class=\"wp-image-8356\" style=\"width:581px;height:auto\" srcset=\"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero.webp 900w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero-300x200.webp 300w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero-768x512.webp 768w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero-640x427.webp 640w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">What happened<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers observed attackers tampering with website infrastructure and <strong>server-side DNS<\/strong> behavior so that the <em>website<\/em> made special DNS queries and, in certain conditions, redirected visitors to malicious content. Because these look like normal DNS operations and occur on the server side, the activity is easy to miss during routine scans.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why this attack is so sneaky<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\"><strong>DNS-level control:<\/strong> Malicious instructions were delivered through DNS (including TXT responses), letting attackers steer traffic or fetch code without obvious on-page clues.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Conditional delivery:<\/strong> Redirects only trigger for certain geos\/devices\/IPs, keeping the campaign low-noise and hard to reproduce.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Long dwell time:<\/strong> DNS-layer manipulation can persist for months without targeted DNS and web telemetry.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">What Strela Stealer actually steals<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Strela<\/em> is an \u201cinfostealer\u201d that focuses on harvesting <strong>email credentials<\/strong>\u2014notably from Microsoft Outlook and Mozilla Thunderbird\u2014and increasingly from browsers and other sources. Stolen logins fuel Business Email Compromise (BEC), payroll fraud, cloud takeovers, or can be sold for further intrusions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to check if you\u2019re affected<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"has-medium-font-size\"><strong>Audit DNS and registrar access:<\/strong> Review A\/CNAME\/TXT records, recent changes, API tokens, and user roles. Turn on change logging.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Inspect redirects:<\/strong> Check server configs, reverse proxies, <code>.htaccess<\/code>, CMS settings, and any plugin\/module that can alter redirects.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Hunt in logs:<\/strong> Look for unusual referrers, user-agent spikes, or geo-specific anomalies in WAF\/CDN and web logs.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Sweep endpoints:<\/strong> Run EDR\/AV hunts for infostealers, browser credential dumpers, and persistence mechanisms on admin workstations and web servers.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Rotate credentials + enforce MFA:<\/strong> Email, registrar\/DNS, CMS, hosting, and critical SaaS. Assume saved credentials may be exposed.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Preventive steps we recommend<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1) Lock down your domain &amp; DNS<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\">Enable <strong>MFA<\/strong> at your registrar\/DNS provider; restrict roles and rotate API tokens.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Set up <strong>change alerts<\/strong> for DNS edits and retain logs.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Use <strong>protective DNS<\/strong> that inspects queries and blocks known-bad destinations.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Consider <strong>DNSSEC<\/strong> to improve record integrity (not a silver bullet).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2) Harden your website &amp; endpoints<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\">Patch CMS, plugins, and themes; remove abandoned components.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Deploy a <strong>WAF\/CDN<\/strong> with bot management and OWASP rules.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Run <strong>EDR<\/strong> on all workstations\/servers; block credential dumping and suspicious browser injections.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Apply least-privilege on web hosts; separate admin\/publisher roles; enforce SSO\/MFA.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"600\" src=\"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-registrar-mfa-security-middle.webp\" alt=\"Enable MFA and change alerts at your DNS registrar to prevent domain hijacking\" class=\"wp-image-8357\" style=\"width:544px;height:auto\" srcset=\"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-registrar-mfa-security-middle.webp 900w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-registrar-mfa-security-middle-300x200.webp 300w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-registrar-mfa-security-middle-768x512.webp 768w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-registrar-mfa-security-middle-640x427.webp 640w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">3) Add monitoring for changes &amp; anomalies<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\">Continuously monitor DNS for drift; alert on unexpected TXT\/redirect patterns.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Enable <strong>UEBA\/SIEM<\/strong> detections for mass email-rule changes, repeated failed logins, and unusual data egress.<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Back up site code\/configs; <strong>test restores<\/strong> and keep periodic offline copies.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">If you suspect compromise: 5 immediate steps<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"has-medium-font-size\"><strong>Freeze DNS<\/strong> changes and rotate registrar\/DNS credentials and API tokens.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Remove malicious records<\/strong>, redirects, or injected code; redeploy clean artifacts.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Force credential resets<\/strong> (email, CMS, hosting, SaaS) and enforce MFA.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Re-baseline endpoints<\/strong> involved in admin work or site maintenance; image if needed and rescan.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Notify impacted users<\/strong> if credentials or personal data may be exposed; involve legal\/compliance as required.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">How Landon Technologies can help<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We offer a rapid <strong>DNS &amp; Website Integrity Check<\/strong> for SMBs: registrar\/DNS hardening, DNS drift review, CMS\/plugin audit, WAF\/EDR validation, and continuous monitoring options. Need help now? <a href=\"https:\/\/www.landontechnologies.com\/contact-us\/\">Schedule a quick consult<\/a> or call us.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-security-quick-consult-cta-1024x683.jpg\" alt=\"SMB cybersecurity expert auditing DNS and website integrity\" class=\"wp-image-8358\" style=\"width:568px;height:auto\" srcset=\"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-security-quick-consult-cta-1024x683.jpg 1024w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-security-quick-consult-cta-300x200.jpg 300w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-security-quick-consult-cta-768x512.jpg 768w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-security-quick-consult-cta-1248x832.jpg 1248w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-security-quick-consult-cta-640x427.jpg 640w, https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-security-quick-consult-cta.jpg 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Explore our related services:<\/em> <a href=\"https:\/\/www.landontechnologies.com\/cybersecurityservices\/\" type=\"link\" id=\"https:\/\/www.landontechnologies.com\/cybersecurityservices\/\">Cybersecurity Services<\/a> \u00b7 <a href=\"https:\/\/www.landontechnologies.com\/managed-it-services\/\">Managed IT Services<\/a> \u00b7 <a href=\"https:\/\/www.landontechnologies.com\/remote-it-support\/\">Remote IT Support<\/a> \u00b7 <a href=\"https:\/\/www.landontechnologies.com\/managed-it-services\/backup-disaster-recovery\/\" type=\"link\" id=\"https:\/\/www.landontechnologies.com\/managed-it-services\/backup-disaster-recovery\/\">Disaster Recovery Services<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">DNS Malware: Frequently Asked Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Does 8.8.8.8 block malware?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No, <strong>8.8.8.8<\/strong> \u2014 which is Google Public DNS \u2014 does not primarily function as a malware-blocking DNS service. Its main purpose is fast and reliable DNS resolution, helping devices translate website names into IP addresses. While Google Public DNS may provide some basic protections against certain dangerous or invalid domains, it is not designed to actively filter malware, phishing sites, adult content, or malicious traffic the way dedicated security-focused DNS services do.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What are the signs of DNS hijacking?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Common signs of DNS hijacking include being redirected to the wrong websites, seeing unexpected advertisements or pop-ups, security certificate warnings, unusually slow browsing, fake login pages, or websites looking different than normal. Other warning signs can include changes to your DNS settings without permission, antivirus alerts about suspicious network activity, inability to reach certain websites, or multiple devices on the same network experiencing strange browsing behavior. DNS hijacking occurs when attackers manipulate DNS settings or responses to redirect internet traffic to malicious or fraudulent websites.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How to test malware blocking DNS?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can test a malware-blocking DNS service by using safe test domains specifically designed to verify DNS filtering without exposing your device to real malware. Security-focused DNS providers such as Quad9, Cloudflare Family\/Malware DNS, and Cisco Umbrella often provide official test URLs or blocked-domain examples.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What are the most common DNS attacks?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some of the most common DNS attacks include <strong>DNS hijacking, DNS spoofing (cache poisoning), DNS tunneling, DDoS attacks against DNS servers, and NXDOMAIN attacks<\/strong>. DNS hijacking redirects users to malicious websites by changing DNS settings, while DNS spoofing injects false DNS information into caches so users are sent to fraudulent destinations. DNS tunneling hides malicious traffic inside DNS queries to bypass security controls, and DNS-based DDoS attacks overwhelm DNS servers to disrupt internet access. Attackers also use NXDOMAIN floods and amplification attacks to overload systems and degrade network performance.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Sources &amp; Further Reading<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\"><a href=\"https:\/\/www.techradar.com\/pro\/security\/dangerous-dns-malware-infects-over-30-000-websites-so-be-on-your-guard\" target=\"_blank\" rel=\"noreferrer noopener\">TechRadar: Dangerous DNS malware infects over 30,000 websites \u2014 be on your guard<\/a> (Oct 3, 2025)<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/detour-dog-dns-malware-powers-strela-stealer-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">Infoblox Threat Intel: Detour Dog \u2014 DNS malware powers Strela Stealer campaigns<\/a> (Sep 30, 2025)<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><a href=\"https:\/\/www.ibm.com\/think\/x-force\/strela-stealer-todays-invoice-tomorrows-phish\" target=\"_blank\" rel=\"noreferrer noopener\">IBM X-Force: Strela Stealer \u2014 \u201cToday\u2019s invoice is tomorrow\u2019s phish\u201d<\/a> (Nov 2024)<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/strelastealer-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener\">Palo Alto Networks Unit 42: Large-Scale StrelaStealer Campaign in Early 2024<\/a> (Mar 22, 2024)<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><a href=\"https:\/\/attack.mitre.org\/software\/S1183\/\" target=\"_blank\" rel=\"noreferrer noopener\">MITRE ATT&amp;CK: StrelaStealer (S1183)<\/a> (Last updated Mar 10, 2025)<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><a href=\"https:\/\/media.defense.gov\/2025\/Mar\/24\/2003675043\/-1\/-1\/0\/CSI-Selecting-a-Protective-DNS-Service-v1.3.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">NSA\/CISA: Selecting a Protective DNS Service<\/a> (Apr 2025)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Last checked: Oct 3, 2025<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udee1\ufe0f <strong>Cybersecurity<\/strong><\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\ud83d\udee1\ufe0f <strong>Stay Ahead of Cyber Threats<\/strong><br>Get the latest security insights and tips in our<br>\ud83d\udc49 <a class=\"\" href=\"https:\/\/www.landontechnologies.com\/blog\/category\/cybersecurity\/\"><strong>Cybersecurity Blog Category<\/strong><\/a><\/p>\n<\/blockquote>\n\n\n\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does 8.8.8.8 block malware?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"No, Google Public DNS (8.8.8.8) is primarily designed for fast and reliable DNS resolution rather than active malware blocking. While it may provide limited protection against certain dangerous domains, it is not intended to function as a dedicated malware-filtering DNS service like Quad9, Cisco Umbrella, or Cloudflare Malware DNS.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What are the signs of DNS hijacking?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Common signs of DNS hijacking include website redirects, unexpected advertisements, fake login pages, security certificate warnings, unusually slow browsing, unauthorized DNS setting changes, and multiple devices on the same network experiencing abnormal browsing behavior.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How to test malware blocking DNS?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Malware-blocking DNS services can be tested using safe test domains provided by security-focused DNS providers such as Quad9, Cloudflare, or Cisco Umbrella. If the DNS filtering is working properly, the test domain should be blocked or fail to load.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What are the most common DNS attacks?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Common DNS attacks include DNS hijacking, DNS spoofing (cache poisoning), DNS tunneling, DNS amplification attacks, NXDOMAIN attacks, and DDoS attacks against DNS servers. These attacks can redirect users to malicious websites, bypass security controls, or disrupt internet services.\"\n      }\n    }\n  ]\n}\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>A newly reported campaign nicknamed \u201cDetour Dog\u201d quietly compromised more than 30,000 websites by abusing Domain Name System (DNS) logic to redirect visitors and deliver malware, including the Strela info-stealer. Below we break down what happened, why it matters for small and medium-sized businesses, and the practical steps to protect your organization. What happened Researchers [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[42],"tags":[1975,1973,1972,1977,1974,1976],"class_list":["post-8353","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","tag-detour-dog","tag-dns-hijack","tag-dns-security","tag-protective-dns","tag-strela-stealer","tag-website-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know | Landon Technologies, Inc.<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know | Landon Technologies, Inc.\" \/>\n<meta property=\"og:description\" content=\"A newly reported campaign nicknamed \u201cDetour Dog\u201d quietly compromised more than 30,000 websites by abusing Domain Name System (DNS) logic to redirect visitors and deliver malware, including the Strela info-stealer. Below we break down what happened, why it matters for small and medium-sized businesses, and the practical steps to protect your organization. What happened Researchers [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/\" \/>\n<meta property=\"og:site_name\" content=\"Landon Technologies\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-03T15:11:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-30T11:52:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"TechWriter\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TechWriter\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/\"},\"author\":{\"name\":\"TechWriter\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#\\\/schema\\\/person\\\/e95d3a182274cef332a291acd32064e2\"},\"headline\":\"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know\",\"datePublished\":\"2025-10-03T15:11:11+00:00\",\"dateModified\":\"2026-05-30T11:52:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/\"},\"wordCount\":998,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/dns-malware-detour-dog-hero.webp\",\"keywords\":[\"detour dog\",\"dns hijack\",\"dns security\",\"protective dns\",\"strela stealer\",\"website security\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/\",\"url\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/\",\"name\":\"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know | Landon Technologies, Inc.\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/dns-malware-detour-dog-hero.webp\",\"datePublished\":\"2025-10-03T15:11:11+00:00\",\"dateModified\":\"2026-05-30T11:52:25+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/dns-malware-detour-dog-hero.webp\",\"contentUrl\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/dns-malware-detour-dog-hero.webp\",\"width\":900,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/dns-malware-detour-dog\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/\",\"name\":\"Landon Technologies\",\"description\":\"Managed IT Services &amp; Cybersecurity\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#organization\",\"name\":\"Landon Technologies, Inc.\",\"url\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/cropped-landon_technologies_header.png\",\"contentUrl\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/cropped-landon_technologies_header.png\",\"width\":1710,\"height\":408,\"caption\":\"Landon Technologies, Inc.\"},\"image\":{\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.landontechnologies.com\\\/blog\\\/#\\\/schema\\\/person\\\/e95d3a182274cef332a291acd32064e2\",\"name\":\"TechWriter\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5b6b2e8a341a74081340006f0f2ca99554fde6e9300751c634bc1b96c8927c02?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5b6b2e8a341a74081340006f0f2ca99554fde6e9300751c634bc1b96c8927c02?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5b6b2e8a341a74081340006f0f2ca99554fde6e9300751c634bc1b96c8927c02?s=96&d=mm&r=g\",\"caption\":\"TechWriter\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know | Landon Technologies, Inc.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/","og_locale":"en_US","og_type":"article","og_title":"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know | Landon Technologies, Inc.","og_description":"A newly reported campaign nicknamed \u201cDetour Dog\u201d quietly compromised more than 30,000 websites by abusing Domain Name System (DNS) logic to redirect visitors and deliver malware, including the Strela info-stealer. Below we break down what happened, why it matters for small and medium-sized businesses, and the practical steps to protect your organization. What happened Researchers [&hellip;]","og_url":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/","og_site_name":"Landon Technologies","article_published_time":"2025-10-03T15:11:11+00:00","article_modified_time":"2026-05-30T11:52:25+00:00","og_image":[{"width":900,"height":600,"url":"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero.webp","type":"image\/webp"}],"author":"TechWriter","twitter_card":"summary_large_image","twitter_misc":{"Written by":"TechWriter","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/#article","isPartOf":{"@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/"},"author":{"name":"TechWriter","@id":"https:\/\/www.landontechnologies.com\/blog\/#\/schema\/person\/e95d3a182274cef332a291acd32064e2"},"headline":"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know","datePublished":"2025-10-03T15:11:11+00:00","dateModified":"2026-05-30T11:52:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/"},"wordCount":998,"commentCount":0,"publisher":{"@id":"https:\/\/www.landontechnologies.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/#primaryimage"},"thumbnailUrl":"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero.webp","keywords":["detour dog","dns hijack","dns security","protective dns","strela stealer","website security"],"articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/","url":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/","name":"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know | Landon Technologies, Inc.","isPartOf":{"@id":"https:\/\/www.landontechnologies.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/#primaryimage"},"image":{"@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/#primaryimage"},"thumbnailUrl":"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero.webp","datePublished":"2025-10-03T15:11:11+00:00","dateModified":"2026-05-30T11:52:25+00:00","breadcrumb":{"@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/#primaryimage","url":"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero.webp","contentUrl":"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/10\/dns-malware-detour-dog-hero.webp","width":900,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/www.landontechnologies.com\/blog\/dns-malware-detour-dog\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.landontechnologies.com\/blog\/"},{"@type":"ListItem","position":2,"name":"DNS Malware Is Back in the Headlines \u2014 What SMBs Need to Know"}]},{"@type":"WebSite","@id":"https:\/\/www.landontechnologies.com\/blog\/#website","url":"https:\/\/www.landontechnologies.com\/blog\/","name":"Landon Technologies","description":"Managed IT Services &amp; Cybersecurity","publisher":{"@id":"https:\/\/www.landontechnologies.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.landontechnologies.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.landontechnologies.com\/blog\/#organization","name":"Landon Technologies, Inc.","url":"https:\/\/www.landontechnologies.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.landontechnologies.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/04\/cropped-landon_technologies_header.png","contentUrl":"https:\/\/www.landontechnologies.com\/blog\/wp-content\/uploads\/2025\/04\/cropped-landon_technologies_header.png","width":1710,"height":408,"caption":"Landon Technologies, Inc."},"image":{"@id":"https:\/\/www.landontechnologies.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.landontechnologies.com\/blog\/#\/schema\/person\/e95d3a182274cef332a291acd32064e2","name":"TechWriter","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/5b6b2e8a341a74081340006f0f2ca99554fde6e9300751c634bc1b96c8927c02?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/5b6b2e8a341a74081340006f0f2ca99554fde6e9300751c634bc1b96c8927c02?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5b6b2e8a341a74081340006f0f2ca99554fde6e9300751c634bc1b96c8927c02?s=96&d=mm&r=g","caption":"TechWriter"}}]}},"_links":{"self":[{"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/posts\/8353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/comments?post=8353"}],"version-history":[{"count":14,"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/posts\/8353\/revisions"}],"predecessor-version":[{"id":9874,"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/posts\/8353\/revisions\/9874"}],"wp:attachment":[{"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/media?parent=8353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/categories?post=8353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.landontechnologies.com\/blog\/wp-json\/wp\/v2\/tags?post=8353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}