logo

New Morphing Meerkat Phishing Kit Exploits DNS to Spoof 100+ Brands

ID: da25f5d7-0f9c-554c-92f5-1261d145e0f0

STIX ID: report--da25f5d7-0f9c-554c-92f5-1261d145e0f0

Feed Name: HackRead

Threat Score
70/100

Date Published: 2025-03-28

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Infoblox researchers describe "Morphing Meerkat," a sophisticated phishing-as-a-service operation that has abused DNS MX records, DNS-over-HTTPS (DoH), open redirects on adtech platforms, and compromised WordPress sites to dynamically serve over 114 brand-specific fake login pages and harvest credentials via EmailJS, PHP/AJAX, and Telegram hooks. The platform centralizes spam distribution through specific hosting providers, implements cloaking and anti-analysis techniques, supports multi-language translation, and has evolved since 2020 to increase its reach and evasion — prompting recommendations to tighten DNS security, restrict DoH, and limit access to non-essential infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.