logo

Morphing Meerkat’s Phishing Tactics: Abusing DNS MX Records

ID: 844475a6-8d1f-51f6-bf08-e9e9cac378ed

STIX ID: report--844475a6-8d1f-51f6-bf08-e9e9cac378ed

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2025-04-01

Date Updated: 2026-04-22

Author: do son

...
...

**Executive Summary:** Infoblox Threat Intelligence describes "Morphing Meerkat," a sophisticated phishing PhaaS that uses DNS MX lookups (via DoH), adtech redirects, obfuscated JavaScript, and dynamic templates to present localized fake login pages for 114+ brands and exfiltrate credentials via EmailJS, PHP/AJAX, and Telegram bots; recommended mitigations include blocking DoH, restricting non-essential adtech/file-sharing access, monitoring MX queries, and deploying DNS-layer phishing detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.