Muddling Meerkat hackers manipulate DNS using China’s Great Firewall
ID: 0190f2a7-8109-5b3f-b59b-94da13ee3d20
STIX ID: report--0190f2a7-8109-5b3f-b59b-94da13ee3d20
Feed Name: Bleeping Computer
Threat Score
A new cluster of activity called “Muddling Meerkat,” attributed to a Chinese state-sponsored operator, manipulates DNS—including injecting false MX record responses via the Great Firewall and using open resolvers and random subdomain queries—to probe networks, test resilience, and potentially misdirect email; Infoblox observed this activity since October 2019 with a spike in September 2023 and published IoCs and TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
