• This new phishing campaign can tailor its messages to target you

    From TechnologyDaily@1337:1/100 to All on Fri Mar 28 15:15:08 2025
    This new phishing campaign can tailor its messages to target you with your favorite businesses

    Date:
    Fri, 28 Mar 2025 15:03:00 +0000

    Description:
    Security researchers from Infoblox found a new phishing kit called Morphing Meerkat.

    FULL STORY ======================================================================Morphing
    Meerkat phishing kit can spoof more than 100 different brands It's been used to send "thousands" of emails, experts warn Defenses includes adding a strong layer of DNS security

    Cybercriminals have created a new technique to serve phishing emails to business users which are almost indistinguishable from legitimate messages.

    Cybersecurity researchers Infoblox spotted the Phishing-as-a-Service (PhaaS) kit, built by a threat actor dubbed Morphing Meerkat, which deploys DNS Mail exchange (MX) records, dynamically serving fake login pages.

    The technique allows them to spoof more than 100 different brands, making it quite a potent offering for cybercriminals.

    Monitor your credit score with TransUnion starting at $29.95/month

    TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnions advanced risk assessment tools.

    Preferred partner ( What does this mean? ) View Deal Open redirects

    Morphing Meerkats PhaaS platform and phishing kits are unique compared to others because they dynamically serve phishing login webpages based on the
    DNS MX record of each victims email domain, the researchers explained, saying that it lets the attackers display web content strongly related to the
    victims email service provider.

    The overall phishing experience feels natural because the design of the landing page is consistent with the spam emails message, they added.

    Morphing Meerkat hasnt exactly drawn much attention to itself yet, which
    might sound rather surprising given the fact that it sent thousands of spam emails from servers mostly located in the UK and the United States.

    However, the researchers said the operation is difficult to detect at scale, since the attackers know where security blind spots are, and have been exploiting them via open redirects on adtech, DoH communication, and popular file-sharing services.

    To protect themselves, organizations should add a strong layer of DNS
    security to their systems, Infoblox concludes, which includes tightening DNS controls and not allowing users to communicate with DoH servers.

    If companies can reduce the number of unimportant services in their network, they can reduce their attack surface, giving few options to cybercriminals
    for threat delivery, Infoblox concluded. You might also like Massive online data breach sees 2.7 billion records leaked - here's what we know We've rounded up the best password managers Take a look at our guide to the best authenticator app



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/this-new-phishing-campaign-can-tailor-i ts-messages-to-target-you-with-your-favorite-businesses


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)