A hacker alters IP addresses attached to domains in a DNS server with a fake DNS entry.
That’s how DNS poisoning or spoofing works:
A hacker alters IP addresses attached to domains in a DNS server with a fake DNS entry.
The IP address returns a domain that looks like the users intended site.