Glossary
Local recursive resolver hijacking
Local recursive resolver hijacking is an attack that compromises a local DNS resolver—typically found on home routers, broadband modems, or other customer premises equipment (CPE)—and manipulates DNS responses provided to users and devices on the network. By altering DNS settings or redirecting DNS queries, attackers can send users to malicious websites, intercept sensitive information, or facilitate additional cyberattacks.
As remote work and home networking have become more common, compromised local DNS infrastructure has become an increasingly important security concern for both individuals and organizations.
{{anchor:Overview}}
How local recursive resolver hijacking works
Many home routers and broadband devices provide local DNS resolution services for devices connected to the network.
Attackers may compromise these systems through:
- Vulnerable or outdated device firmware
- Weak or default administrative credentials
- Phishing attacks targeting device administrators
- Browser-based attacks against management interfaces
- Misconfigured remote management services
Once access is obtained, attackers can:
- Modify DNS settings
- Redirect DNS queries to attacker-controlled resolvers
- Manipulate DNS responses
- Redirect users to phishing or malware distribution sites
- Intercept internet traffic and sensitive information
Because DNS operates behind the scenes, users may be unaware that their traffic is being manipulated.
{{anchor:Why it matters}}
Why local recursive resolver hijacking matters
Compromised local DNS resolvers can create significant risks for both consumers and organizations, including:
- Credential theft through phishing sites
- Malware infections and malicious downloads
- Unauthorized access to sensitive business systems
- Exposure of personal and corporate data
- Network performance and reliability issues
- Expanded attack paths into enterprise environments
Organizations with remote employees are particularly vulnerable because compromised home networks can become a pathway to broader business risks.
{{anchor:Prevention}}
Reducing local recursive resolver hijacking risk
Organizations and users can reduce exposure by:
- Keeping router and network device firmware up to date
- Replacing unsupported or end-of-life networking equipment
- Using strong passwords and multi-factor authentication where available
- Restricting administrative access to network devices
- Monitoring for unauthorized DNS changes
- Implementing DNSSEC for domain protection
- Conducting regular security assessments
- Leveraging protective DNS services
A proactive approach to DNS and network security can significantly reduce the likelihood and impact of resolver compromise.
{{anchor:How DigiCert helps}}
How DigiCert can help
DigiCert UltraDDR helps organizations protect users and devices from malicious DNS activity through advanced protective DNS capabilities. By leveraging real-time threat intelligence and continuous monitoring of malicious infrastructure, UltraDDR can identify and block connections to phishing sites, malware delivery domains, and other malicious destinations before users can interact with them.
UltraDDR provides protection regardless of location, helping secure remote users who may be connected through home networks, public Wi-Fi, or other environments where local DNS infrastructure could be compromised. By reducing reliance on potentially untrusted DNS resolvers and providing visibility into DNS activity, UltraDDR helps organizations strengthen cyber resilience and reduce exposure to DNS-based threats.
In addition, DigiCert UltraDNS provides secure, enterprise-grade authoritative DNS services with DNSSEC support, helping organizations strengthen DNS integrity and reduce the risk of DNS manipulation. Built on a globally distributed Anycast architecture, UltraDNS helps maintain trusted and resilient DNS services that support secure digital operations.
Together, DigiCert UltraDDR and UltraDNS help organizations strengthen DNS security, protect remote users, and maintain trusted digital experiences in an evolving threat landscape.