A DNS hijack means that someone has intentionally modified the settings on your router without your consent. This type of attack allows an attacker to monitor, control, or redirect your Internet traffic. DNS hijacking can alter the advertisements you see while browsing. DNS hijacking takes advantage of how the Domain Name System functions as the internet's phone book—or more accurately, a series of phone books that a browser checks, with each book telling a browser where to go next. This malware modifies a computer's Domain Name Service (DNS) settings and thereby directs the computers to receive potentially improper results from rogue DNS servers hosted by the defendants.

Diagnosing DNS hijacking isn’t very simple since there is no “Yes or No” DNS hijacking test you can run. And if you’re not paying enough attention to the website you land on, you might not even realize it’s the wrong one or a fake one. The best way to spot DNS hijacking is to …

Hacker group has been hijacking DNS traffic on D-Link routers for three months. Other router models have also been targeted, such as ARG, DSLink, Secutech, and TOTOLINK. One of the easiest way to determine DNS hijacking is using the ping utility. If you ping a domain that doesn't exist, and it resolves, there's a good chance that your DNS traffic is being hijacked. After taking over your router, attackers modify its settings. They change the addresses of the DNS servers the router uses to resolve domain names. The DNS (Domain Name System) is the pillar of the Internet. Whenever I do a Google search (or BING, or any search), I get results, but when I click on those results, I always get to SCOUR.COM (or some affiliate).

DNS protocol is a very critical component of the Internet as it resolves IP-address into hostnames and makes life a lot easier for us. However, if the nameservers are not properly configured they might leak out the whole DNS server database to any malicious hacker.