PULSE NAME
Discovers Multiyear Sophisticated Chinese DNS Operation
WHITE Muddling Meerkat AlienVault 2024-04-29 Modified: 2024-05-29
5
IOCs
LOW VOLUME
This report unveils a previously undisclosed multiyear operation conducted by a sophisticated actor called Muddling Meerkat. The operation employs Domain Name System (DNS) queries, open DNS resolvers, and interacts with China's Great Firewall. The tactics demonstrate the actor's ability to conduct extended covert operations, analogous to the recent compromise of the xz open source library. Muddling Meerkat appears to be a Chinese nation-state actor leveraging DNS infrastructure for unclear motives.
Indicators of Compromise (5)
All domain email
TYPEINDICATORDESCRIPTIONCREATED
domain boxi.com 2024-04-29
domain diggui.com 2024-04-29
domain gogo.com 2024-04-29
domain zbo6.com 2024-04-29
email ricci@discuss.systems 2024-04-29