logo

Muddling Meerkat Group Suspected of Espionage via Great Firewall of China

ID: d3ee63a0-10cc-50ef-82aa-d1bf0e1ac567

STIX ID: report--d3ee63a0-10cc-50ef-82aa-d1bf0e1ac567

Feed Name: HackRead

Threat Score
85/100

Date Published: 2024-05-01

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Infoblox and partners describe a Chinese state-linked threat actor named "Muddling Meerkat" that has operated since 2019 by manipulating DNS and apparently influencing China’s Great Firewall (GFW). The actor demonstrates advanced DNS expertise (including generating false MX records from Chinese IPs), leverages open DNS resolvers globally, and may be conducting reconnaissance or preparing for large-scale DNS denial-of-service activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.