Glossary

Stub resolver hijacking

Stub Resolver Hijacking

Stub resolver hijacking is an attack that compromises a device’s local DNS resolution process by modifying the operating system’s DNS settings, host file, or stub resolver configuration. By manipulating how DNS queries are resolved, attackers can redirect users to malicious websites, intercept network traffic, or facilitate phishing, malware delivery, and data theft.

Because nearly all internet communications begin with a DNS query, compromising the local DNS resolution process can have far-reaching security implications for both individuals and organizations.

{{anchor:How stub resolver hijacking works}}

How stub resolver hijacking works

A DNS stub resolver is the component within an operating system that receives DNS queries from applications and forwards them to a recursive DNS resolver.

Attackers typically compromise this process by:

Once compromised, attackers can manipulate DNS responses and redirect users to malicious destinations without their knowledge.

{{anchor:Why it matters}}

Why stub resolver hijacking matters

Stub resolver hijacking is often used to support:

Because users often believe they are visiting legitimate websites, these attacks can be highly effective and difficult to detect without appropriate security controls.

{{anchor:Business impact}}

Business impact

Successful stub resolver hijacking can result in:

Organizations with distributed workforces and unmanaged endpoints may face increased risk if local DNS settings are compromised.

{{anchor:Reducing risk}}

Reducing stub resolver hijacking risk

Organizations can strengthen defenses against stub resolver hijacking by:

A layered security strategy helps reduce opportunities for attackers to manipulate DNS resolution at the endpoint level.

{{anchor:How DigiCert helps}}

How DigiCert can help

DigiCert UltraDDR helps organizations defend against DNS-based threats through advanced protective DNS capabilities. By leveraging real-time threat intelligence and continuously monitoring malicious infrastructure, UltraDDR can identify and block access to phishing sites, malware delivery domains, and other malicious destinations before users can connect to them.

UltraDDR provides protection for users regardless of location, helping reduce reliance on potentially compromised network-provided DNS resolvers in environments such as public Wi-Fi, hotels, coffee shops, and home networks. By providing visibility into DNS activity and enforcing security policies at the DNS layer, UltraDDR helps organizations reduce exposure to DNS manipulation and strengthen cyber resilience.

In addition, DigiCert UltraDNS provides enterprise-grade authoritative DNS services with DNSSEC support, helping organizations strengthen DNS integrity and reduce the risk of DNS-related attacks. Built on a globally distributed Anycast architecture, UltraDNS helps maintain secure, resilient, and highly available DNS infrastructure that supports trusted digital experiences.

Together, DigiCert UltraDDR and UltraDNS help organizations protect users, devices, and networks from evolving DNS threats while maintaining secure and reliable digital operations.