HomeSecurityMuddling Meerkat: Manipulates DNS through the Great Firewall

Muddling Meerkat: Manipulates DNS through the Great Firewall

A new type of malicious activity, known as “Muddling Meerkat,” is believed to be linked to DNS manipulation by a Chinese state-sponsored malicious actor to probe networks worldwide since October 2019, with a spike in activity observed in September 2023.

See also: KeyTrap vulnerability: Interrupting internet access with DNS packet

Muddling Meerkat

A notable aspect of Muddling Meerkat's activity is the manipulation of MX (Mail Exchange) records by inserting fake responses through China's Great Firewall (GFW) , an unusual and invisible behavior for the country's internet censorship system

The malicious activity, discovered by Infoblox, has no clear goal or motive, but it demonstrates sophistication and advanced capabilities to manipulate global DNS systems. By examining massive volumes of DNS data, Infoblox researchers discovered activity that they say could easily fly under the radar or be considered harmless.

DNS is an essential functional component of the Internet , which translates human-readable domain names into IP addresses that computers use to identify each other on the network and establish connections.

Muddling Meerkat manipulates DNS queries and responses by targeting the mechanism by which resolvers return IP addresses. For example, they can cause bogus MX record responses from GFW to mess with routing and possibly incorrect email addresses.

See also: Infoblox applies AI to DNS Traffic to combat malware

DNS

The Great Firewall of China is an internet control and censorship system used by the Chinese government. This system controls access to foreign websites and filters online content deemed threatening or undesirable by the government. The Great Firewall uses a number of methods to control information circulating on the internet. These include blocking access to foreign websites, monitoring and censoring online content, blocking access to foreign applications, and blocking access to foreign services.

The confusion of Muddling Meerkat's activities forces it to issue fake responses that serve purposes such as testing the resilience and behavior of other networks. To further limit their activities, Muddling Meerkat makes DNS requests for random subdomains of their target domains, which often do not exist.

While this resembles an attack called a “Slow Drip DDoS,” Infoblox notes that in the case of Muddling Meerkat, the queries are small-scale and aimed at testing rather than disrupting. The threat actor also exploits open resolvers to obfuscate their activity and engages both valid and recursive resolvers.

See also: ExpressVPN: Bug in split tunneling feature exposed DNS requests

Infoblox reports that Muddling Meerkat selects target domains with short names registered before 2000, making them less likely to be on DNS block lists.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS