logo

Muddling Meerkat hackers manipulate DNS using China’s Great Firewall

ID: 0190f2a7-8109-5b3f-b59b-94da13ee3d20

STIX ID: report--0190f2a7-8109-5b3f-b59b-94da13ee3d20

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-04-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A new cluster of activity called “Muddling Meerkat,” attributed to a Chinese state-sponsored operator, manipulates DNS—including injecting false MX record responses via the Great Firewall and using open resolvers and random subdomain queries—to probe networks, test resilience, and potentially misdirect email; Infoblox observed this activity since October 2019 with a spike in September 2023 and published IoCs and TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.