logo

Phishing-as-a-service operation uses DNS-over-HTTPS for evasion

ID: ee8963e7-8c83-5328-961e-efe241f7640a

STIX ID: report--ee8963e7-8c83-5328-961e-efe241f7640a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-03-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Infoblox researchers uncovered 'Morphing Meerkat', a phishing-as-a-service operation active since at least 2020 that uses DNS-over-HTTPS and MX record lookups to dynamically identify victims' email providers and present tailored spoofed login pages for more than 114 brands; the operation employs centralized SMTP infrastructure, open-redirect chains and compromised sites to deliver multilingual phishing, exfiltrates credentials via AJAX/PHP and optional Telegram webhooks, and has associated IoCs published on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.