Isn’t dns hijacking a major problem? I could go to a Starbucks and setup my own dhcp server on my laptop. A certain fraction of the WiFi devices would probably pick up my dhcp given dns which would reroute requests to my own dns server. Nobody would ever know... or am I misunderstanding something about https?
Or if I was a malware writer I would discretely target hosts files or the local dns configuration - exploits in certain routers to try to reconfigure the complete local network and such.