DetourDog malware campaign compromised over 30,000 websites using DNS redirectionVictims were silently redirected to sites hosting Strela Stealer, a modular infostealerAttack remained undetected for months due to DNS-level manipulation and infrastructure abuseSecurity researchers have spotted an enormous malware campaign which managed to quietly compromise more than 30,000 websites, as well as countless visitors. Since the DNS requests are made from the website itself, rather than the visitors, they are invisible to the victims. Strela StealerInfoblox’s analysis also revealed that the attackers used a combination of compromised registrars, DNS providers, and misconfigured domains to propagate DetourDog. The victims are redirected from legitimate (but compromised) websites, to those hosting an infostealer called Strela Stealer. Strela Stealer itself was first spotted in late 2022.