Infoblox announced that its threat intel researchers, in collaboration with external researchers, have uncovered ‘Muddling Meerkat’, a likely PRC state actor with the ability to control the Great Firewall (GFW) of China, a system that censors and manipulates traffic entering and exiting China’s internet.
This domain name system (DNS) threat actor is particularly sophisticated in its ability to bypass traditional security measures, as it conducts operations by creating large volumes of widely distributed DNS queries that are subsequently propagated through the internet through open DNS resolvers. Infoblox leveraged its deep understanding and unique access to DNS to discover this cyberthreat, pre-incident, blocking its domains to ensure its customers are safe.
“Infoblox Threat Intel eats, sleeps, and breathes DNS data,” said Dr. Renée Burton, Vice President, Infoblox Threat Intel. “Our unrelenting focus on DNS, using cutting-edge data science and AI, has enabled our global team of threat hunters to be the first to discover Muddling Meerkat lurking in the shadows and produce critical threat intelligence for our customers. This actor’s complex operations demonstrate a strong understanding of DNS, stressing the importance of having a DNS detection and response (DNSDR) strategy in place to stop sophisticated threats like Muddling Meerkat.”
The moniker ‘Muddling Meerkat’ was given to describe the actor as an animal that appears cute, but in reality, it can be dangerous, living in a complex network of burrows underground, and out of view. From a technical perspective, ‘Meerkat’ references the abuse of open resolvers, particularly through the use of DNS mail exchange (MX) records. ‘Muddling’ refers to the bewildering nature of their operations.
With a deep understanding of and visibility into DNS Infoblox Threat Intel can see attacker infrastructure as it’s created, stopping both known and emerging threats earlier. With 46 million unique threat indicators detected in 2023 and a practically non-existent false positive rate of 0.0002 per cent, Infoblox Threat Intel detected 82 per cent of threats before or at the first query thus far in 2024 leveraging our patent pending threat intelligence system along with Infoblox’s new Zero Day DNS capability.
The threat actor, Muddling Meerkat, has been operating covertly since at least October 2019. At first glance, its operations look like Slow Drip distributed denial-of-service (DDoS) attacks, however, it is unlikely DDoS is their ultimate goal. The motivation of the actor is unknown, though they may be performing reconnaissance or prepositioning for future attacks. Muddling Meerkat demonstrates a sophisticated understanding of DNS that is uncommon among threat actors today – clearly pointing out that DNS is a powerful weapon leveraged by adversaries.
The research further shows that their operations:
4 days ago
QDSA announces defence grant winners – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
4 days ago
Airbus expands its Earth observation constellation – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
4 days ago
Raytheon wins contact for missile system electronics unit – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
4 days ago
Australia backs Space Machines in joint India mission – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
4 days ago
Boeing T-7A Red Hawk triples testing progress – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
5 days ago
Video
Share on Facebook Share on Twitter Share on Linked In Share by Email
5 days ago
Australia, NZ join Exercise Tagata Toa 24 – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
5 days ago
Boeing wins deal for MH-139A helicopters – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
5 days ago
New threat actor controlling China’s Great Firewall – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
6 days ago
Singapore Air Force personnel training at RAAF Base Richmond – APDR
asiapacificdefencereporter.com
Share on Facebook Share on Twitter Share on Linked In Share by Email
Twitter Activity Follow
Australian Defence In a Global Context. In its 47th year APDR is the longest established defence publication in Australia.
US Commerce Dept. cuts some requirements to advance AUKUS
First RAN officers assigned to US Virginia-class submarines
Boeing P-8A aircraft contract bolsters Australia maritime defence
HD HHI wins deal for Peruvian Navy vessels
NZAero signs MOU for Thai government aircraft
Northrop Grumman expands Australia MQ-4C Triton support team
IAI sells integrated air defence radar to European customer
Milrem Robotics to deliver THeMIS UGVs to Japan
First satellite of South Korea “425 Project” launched
From the Magazine: Navy surface fleet facing a worrying fall in numbers later this decade

More Stories
Community Snapshot—June
New ITU Report Finds Community Networks Are Key to Reaching the Unconnected
Digital Coercion: How Inaccessible Design Strips Financial Privacy