Accessibility Statement Skip Navigation
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • Data Privacy
  • Français
  • my CNW 
    • Login
    • Register
  • Client Login 
    • Online Member Centre
    • Next Gen Communications Cloud
    • Cision Communications Cloud®
  • Sign Up
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
Advanced Search
  • News in Focus
      • Browse News Releases

      • All News Releases
      • All Public Company
      • News Releases Overview

      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
      • Multimedia Gallery Overview

      • Trending Topics

      • All Trending Topics
  • Business
      • Auto & Transportation

      • All Automotive & Transportation
      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • Auto & Transportation Overview

      • View All Auto & Transportation

      • Business Technology

      • All Business Technology
      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • Business Technology Overview

      • View All Business Technology

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Financial Services & Investing

      • All Financial Services & Investing
      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • Financial Services & Investing Overview

      • View All Financial Services & Investing

      • General Business

      • All General Business
      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • General Business Overview

      • View All General Business

  • Science & Tech
      • Consumer Technology

      • All Consumer Technology
      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • Consumer Technology Overview

      • View All Consumer Technology

      • Energy & Natural Resources

      • All Energy
      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • Energy & Natural Resources Overview

      • View All Energy & Natural Resources

      • Environ­ment

      • All Environ­ment
      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • Environ­ment Overview

      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • All Heavy Industry & Manufacturing
      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • Heavy Industry & Manufacturing Overview

      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • All Telecomm­unications
      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • Telecomm­unications Overview

      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • All Consumer Products & Retail
      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • Consumer Products & Retail Overview

      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Health

      • All Health
      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • Health Overview

      • View All Health

      • Sports

      • All Sports
      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • Sports Overview

      • View All Sports

      • Travel

      • All Travel
      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • Travel Overview

      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • All Policy & Public Interest
      • Advocacy Group Opinion
      • Animal Welfare
      • Canadian Federal Government
      • Canadian Municipal Government
      • Canadian Provincial Government
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • Policy & Public Interest Overview

      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • All People & Culture
      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • People & Culture Overview

      • View All People & Culture

  • Advanced Search
  • Overview
  • Cision Communications Cloud®
  • Monitoring
  • Distribution
  • Multimedia
  • Guaranteed Paid Placement
  • AI Tools
  • IR
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media
  • Worldwide Offices
  • Hamburger menu
  • Cision Canada
  • Send a Release
  • FR
    • Phone

    • 877-269-7890 from 8 AM - 10 PM ET

    • ALL CONTACT INFO
    • Contact Cision

      877-269-7890
      from 8 AM - 10 PM ET

  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
    • Trending Topics
  • Business
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
    • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • Overview
  • Cision Communications Cloud®
  • Monitoring
  • Distribution
  • Multimedia
  • Guaranteed Paid Placement
  • AI Tools
  • IR
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media
  • Worldwide Offices
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR

Infoblox Threat Intel Discovers Muddling Meerkat, a DNS Operation Controlling China's Great Firewall

No caption needed for the logo

News provided by

Infoblox Inc.

Apr 29, 2024, 09:00 ET

Share this article

Share toX

Share this article

Share toX

  • Muddling Meerkat utilizes sophisticated DNS activities, likely propagated by Chinese state actors, to bypass traditional security measures and probe networks worldwide
  • With market-leading DNS expertise, backed by data science and AI, Infoblox Threat Intel hunts, tracks and stops threats lurking in DNS, up to 60+ days before other security tools
  • Infoblox Threat Intel enables Infoblox BloxOne® Threat Defense customers to see who and what connects to their network – disrupting threat actors' operations and infrastructure pre-incident
  • Infoblox introduces Zero Day DNS™ feature that detects and blocks attacks launched from domains immediately used after registration as part of a zero trust model for DNS

SANTA CLARA, Calif., April 29, 2024 /CNW/ -- Infoblox Inc., a leader in cloud networking and security services, today announced that its threat intel researchers, in collaboration with external researchers, have uncovered "Muddling Meerkat," a likely PRC state actor with the ability to control the Great Firewall (GFW) of China, a system that censors and manipulates traffic entering and exiting China's internet. This DNS threat actor is particularly sophisticated in its ability to bypass traditional security measures, as it conducts operations by creating large volumes of widely distributed DNS queries that are subsequently propagated through the internet through open DNS resolvers. Infoblox leveraged its deep understanding and unique access to DNS to discover this cyberthreat, pre-incident, blocking its domains to ensure its customers are safe.

Infoblox discovers Muddling Meerkat - the Great Firewall Manipulator.
Infoblox discovers Muddling Meerkat - the Great Firewall Manipulator.
Infoblox discovered several threat actors using DNS throughout 2023 and 2024 including: Decoy Dog, Prolific Puma, Savvy Seahorse, VexTrio Viper and Muddling Meerkat.
Infoblox discovered several threat actors using DNS throughout 2023 and 2024 including: Decoy Dog, Prolific Puma, Savvy Seahorse, VexTrio Viper and Muddling Meerkat.
Infoblox Threat Intel gets a bold new look, demonstrating industry-leading commitment to DNS Threat Intelligence.
Infoblox Threat Intel gets a bold new look, demonstrating industry-leading commitment to DNS Threat Intelligence.
Infoblox discovers Muddling Meerkat - the Great Firewall Manipulator. Infoblox discovered several threat actors using DNS throughout 2023 and 2024 including: Decoy Dog, Prolific Puma, Savvy Seahorse, VexTrio Viper and Muddling Meerkat. Infoblox Threat Intel gets a bold new look, demonstrating industry-leading commitment to DNS Threat Intelligence.

"Infoblox Threat Intel eats, sleeps, and breathes DNS data," said Dr. Renée Burton, Vice President, Infoblox Threat Intel. "Our unrelenting focus on DNS, using cutting-edge data science and AI, has enabled our global team of threat hunters to be the first to discover Muddling Meerkat lurking in the shadows and produce critical threat intelligence for our customers. This actor's complex operations demonstrates a strong understanding of DNS, stressing the importance of having a DNS detection and response (DNSDR) strategy in place to stop sophisticated threats like Muddling Meerkat."

The moniker "Muddling Meerkat'' was given to describe the actor as an animal that appears cute, but in reality it can be dangerous, living in a complex network of burrows underground, and out of view. From a technical perspective, "Meerkat" references the abuse of open resolvers, particularly through the use of DNS mail exchange (MX) records. "Muddling" refers to the bewildering nature of their operations.

With a deep understanding of and visibility into DNS, Infoblox Threat Intel can see attacker infrastructure as it's created, stopping both known and emerging threats earlier. With 46M unique threat indicators detected in 2023 and a practically non-existent false positive rate of 0.0002%, Infoblox Threat Intel detected 82% of threats before or at the first query thus far in 2024 leveraging our patent pending threat intelligence system along with Infoblox's new Zero Day DNS capability. The threat actor, Muddling Meerkat, has been operating covertly since at least October 2019. At first glance, its operations look like Slow Drip distributed denial-of-service (DDoS) attacks, however, it is unlikely DDoS is their ultimate goal. The motivation of the actor is unknown, though they may be performing reconnaissance or prepositioning for future attacks.

Muddling Meerkat demonstrates a sophisticated understanding of DNS that is uncommon among threat actors today - clearly pointing out that DNS is a powerful weapon leveraged by adversaries.

The research further shows that their operations:

  • Induce responses from the Great Firewall, including false MX records from the Chinese IP address space. This highlights a novel use of national infrastructure as a fundamental part of their strategy.
  • Trigger DNS queries for MX and other record types to domains not owned by the actor, but which reside under well-known top-level domains such as .com and .org. This tactic highlights the use of distraction and obfuscation techniques to hide the real intended purpose.
  • Utilize super-aged domains, typically registered prior to the year 2000, enabling the actor to blend in with other DNS traffic and avoid detection. This further highlights the threat actor's understanding of both DNS and existing security controls.

The full report on Muddling Meerkat can be found here.

Infoblox Threat Intel Gets a Bold New Look, Demonstrating Industry-Leading Commitment to DNS Threat Intelligence

Infoblox Threat Intel is the leading creator of original DNS threat intelligence in the market today. The group, led by Dr. Renée Burton, a 22-year veteran of NSA, is composed of researchers across five countries who have deep expertise in DNS, data science, ML/AI, intelligence analysis, software reverse engineering, and malicious spam detection. Infoblox put a new focus on the team's public identity to distinguish itself from the sea of threat intel aggregators - highlighting its expertise in original DNS threat research.

Throughout the past year, Infoblox Threat Intel was the first to report other DNS threat actors, all of which had gone undetected for over a year by the rest of the industry. These include DNS C2 malware toolkit Decoy Dog, malicious link shortening service provider Prolific Puma, the most extensive known cybercriminal traffic distribution system VexTrio Viper (aka VexTrio), and DNS CNAME redirection network provider Savvy Seahorse. These publications represent a small fraction of the number of DNS threat actors Infoblox Threat Intel has discovered and are tracking.

"The sheer mass of threat actors effectively hiding in the DNS should be a wakeup call for every defender to make DNS threat intelligence an essential part of their strategy," added Burton. "Why? Because more than 92%2 of malware utilizes DNS."

The most effective way to protect against these sophisticated threats is with DNS Detection and Response systems like Infoblox's BloxOne® Threat Defense. Unlike other security solutions that are malware and post-event centric, Infoblox Threat Intel uses a multi-pronged approach to discover threats in DNS.

Introducing Zero Day DNS, the Newest Feature within BloxOne Threat Defense

Infoblox's new cloud-based Zero Day DNS™ augments the existing methods to detect and block possible threats from domains that are registered by threat actors just minutes to hours before being used in an attack. It is a zero trust model for DNS that leverages the extensive visibility Infoblox has to rapidly adjudicate hundreds of thousands of new domains in near real time every day.

While most domains are aged before they are used by attackers, Infoblox has discovered an alarming trend over the last 18 months, where threat actors register lookalike domains and immediately use them in targeted attacks. Zero Day DNS was designed specifically to address this risk.

Zero Day DNS is tailored to individual customer networks, providing a new form of custom threat intel for Infoblox BloxOne Threat Defense Advanced Cloud customers. This capability provides the earliest defense against spearphishing attacks, which were responsible for 66% of all data breaches in 2023 according to Barracuda Networks annual report on phishing trends.1 Initial results show that Zero Day DNS can detect novel threats without risk of blocking vital network access. Over 16% of the flagged domains were deemed malicious within 48 hours by other analytics.

"Zero Day DNS is not just a nice to have, but a strategic advantage in an environment where threat actors, particularly ransomware actors, are using a domain immediately after registration for spearphishing," added Burton.

Meet Infoblox Threat Intel

Dr. Burton will discuss Muddling Meerkat at the RSA Conference in San Francisco, May 6-9. Live sessions will be held at Booth S-726. Visit this here to request a meeting with Infoblox at RSAC 2024.

Additionally, Dr. Burton is hosting a webinar titled: Infoblox Threat Intel – Disrupting Cybercrime Where it Begins – DNS, on May 8 at 10 am PDT. Register to attend here.

About Infoblox
Infoblox unites networking and security to deliver unmatched performance and protection. Trusted by Fortune 100 companies and emerging innovators, we provide real-time visibility and control over who and what connects to your network, so your organization runs faster and stops threats earlier. Visit Infoblox.com, or follow-us on LinkedIn or Twitter.

Media Contacts:
[email protected]
[email protected] 

1 https://www.barracuda.com/reports/spear-phishing-trends-2023
2 https://executivegov.com/2020/06/anne-neuberger-on-nsas-secure-dns-pilot-program/

SOURCE Infoblox Inc.

Modal title

Organization Profile

Infoblox Inc.

    Also from this source

  • Infoblox and Google Cloud Announce Partnership to Deliver Cloud-Native Networking and Security Solutions, Reducing Complexity for Enterprise Customers

  • Infoblox Unveils Game-Changing Universal DDI™ Product Suite to Help NetOps, SecOps, and CloudOps Work Better Together

  • Infoblox Report: Hybrid, Multi-Cloud Leaders in Europe Achieve 50% More Cloud Cost Savings Than Nascent Peers

Contact Cision

  • 866-245-2317
    from 8 AM - 10 PM ET
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media

Products

  • Cision Communications Cloud®
  • Media Monitoring
  • Content Distribution
  • Multimedia Distribution
  • Measurement & Analytics
  • Investor Relations

About

  • About Cision Canada
  • About Cision
  • Media Partners
  • Careers
  • Accessibility Statement
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United States
  • Vietnam

My Services

  • All News Releases
  • Online Member Centre
  • Next Gen Communications Cloud
  • Cision Communications Cloud®
  • my CNW

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Centre
  • Next Gen Communications Cloud
  • Cision Communications Cloud
  • my CNW
877-269-7890
from 8 AM - 10 PM ET
  • Terms of Use
  • Information Security Policy
  • Site Map
  • Cookie Settings
  • Accessibility Statement
Copyright © 2025 CNW Group Ltd. All Rights Reserved. A Cision company.