Glossary
Stub resolver hijacking
Stub resolver hijacking is an attack that compromises a device’s local DNS resolution process by modifying the operating system’s DNS settings, host file, or stub resolver configuration. By manipulating how DNS queries are resolved, attackers can redirect users to malicious websites, intercept network traffic, or facilitate phishing, malware delivery, and data theft.
Because nearly all internet communications begin with a DNS query, compromising the local DNS resolution process can have far-reaching security implications for both individuals and organizations.
{{anchor:How stub resolver hijacking works}}
How stub resolver hijacking works
A DNS stub resolver is the component within an operating system that receives DNS queries from applications and forwards them to a recursive DNS resolver.
Attackers typically compromise this process by:
- Modifying local host files
- Changing DNS server settings
- Replacing or tampering with the stub resolver
- Installing malware that intercepts DNS requests
- Redirecting DNS traffic to attacker-controlled resolvers
Once compromised, attackers can manipulate DNS responses and redirect users to malicious destinations without their knowledge.
{{anchor:Why it matters}}
Why stub resolver hijacking matters
Stub resolver hijacking is often used to support:
- Phishing attacks
- Credential theft
- Malware distribution
- DNS cache poisoning
- Data interception
- Unauthorized access to sensitive systems
Because users often believe they are visiting legitimate websites, these attacks can be highly effective and difficult to detect without appropriate security controls.
{{anchor:Business impact}}
Business impact
Successful stub resolver hijacking can result in:
- Data breaches and information theft
- Exposure of customer and employee data
- Credential compromise
- Regulatory and compliance violations
- Financial losses and legal exposure
- Damage to brand reputation and customer trust
Organizations with distributed workforces and unmanaged endpoints may face increased risk if local DNS settings are compromised.
{{anchor:Reducing risk}}
Reducing stub resolver hijacking risk
Organizations can strengthen defenses against stub resolver hijacking by:
- Deploying endpoint protection and anti-malware solutions
- Implementing DNSSEC
- Securing and monitoring local host files
- Restricting unauthorized system configuration changes
- Conducting regular security awareness training
- Monitoring DNS activity for anomalies
- Using protective DNS services
- Maintaining current operating system and software updates
A layered security strategy helps reduce opportunities for attackers to manipulate DNS resolution at the endpoint level.
{{anchor:How DigiCert helps}}
How DigiCert can help
DigiCert UltraDDR helps organizations defend against DNS-based threats through advanced protective DNS capabilities. By leveraging real-time threat intelligence and continuously monitoring malicious infrastructure, UltraDDR can identify and block access to phishing sites, malware delivery domains, and other malicious destinations before users can connect to them.
UltraDDR provides protection for users regardless of location, helping reduce reliance on potentially compromised network-provided DNS resolvers in environments such as public Wi-Fi, hotels, coffee shops, and home networks. By providing visibility into DNS activity and enforcing security policies at the DNS layer, UltraDDR helps organizations reduce exposure to DNS manipulation and strengthen cyber resilience.
In addition, DigiCert UltraDNS provides enterprise-grade authoritative DNS services with DNSSEC support, helping organizations strengthen DNS integrity and reduce the risk of DNS-related attacks. Built on a globally distributed Anycast architecture, UltraDNS helps maintain secure, resilient, and highly available DNS infrastructure that supports trusted digital experiences.
Together, DigiCert UltraDDR and UltraDNS help organizations protect users, devices, and networks from evolving DNS threats while maintaining secure and reliable digital operations.