Thursday, April 24, 2025
Homecyber securityHackers Exploit DNS MX Records to Create Fake Logins Imitating 100+ Brands

Hackers Exploit DNS MX Records to Create Fake Logins Imitating 100+ Brands

Published on

SIEM as a Service

Follow Us on Google News

Cybersecurity researchers have discovered a sophisticated phishing-as-a-service (PhaaS) platform, dubbed “Morphing Meerkat,” that leverages DNS mail exchange (MX) records to dynamically serve tailored phishing pages mimicking over 100 brands.

The platform, which has been operational since at least January 2020, employs a range of advanced techniques to evade detection and maximize the effectiveness of its phishing campaigns.

DNS Abuse and Dynamic Content Delivery

At the core of Morphing Meerkat’s operation is its innovative use of DNS MX records.

- Advertisement - Google News

The platform queries the MX record of a victim’s email domain using DNS over HTTPS (DoH) services from providers like Cloudflare and Google.

It then uses this information to dynamically load a phishing template that closely matches the victim’s email service provider, creating a more convincing and personalized phishing experience.

 Fake Logins
DHL Express email phishing page

The PhaaS platform maintains a library of at least 114 unique email brand and login designs, allowing it to accurately spoof a wide range of email services.

This technique enables the attackers to conduct highly targeted phishing campaigns at scale, increasing the likelihood of successful credential theft.

Evasion Techniques and Global Reach

Morphing Meerkat employs multiple security evasion features to hinder threat analysis and bypass phishing protection systems.

 Fake Logins
Morphing Meerkat attack chain

According to the Report, these include code obfuscation, inflation of script size with non-functional code, and exploitation of open redirects on adtech infrastructure.

The platform also uses client-side email libraries and messaging app APIs to exfiltrate stolen credentials, making detection more challenging.

The PhaaS operation has a global reach, with the ability to dynamically translate phishing content into over a dozen languages based on the victim’s browser settings.

This multilingual capability, combined with the use of compromised WordPress sites and free web hosting services for distribution, allows the attackers to target users worldwide effectively.

The discovery of Morphing Meerkat highlights the evolving sophistication of phishing attacks and the need for enhanced DNS security measures.

Organizations are advised to implement strong DNS controls, limit access to non-essential services, and educate users about the risks of phishing attempts that may closely mimic legitimate login pages.

Are you from SOC/DFIR Teams? – Analyse Malware, Phishing Incidents & get live Access with ANY.RUN -> Start Now for Free. 

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Blue Shield Exposed Health Data of 4.7 Million via Google Ads

Blue Shield of California has disclosed a significant data privacy incident affecting up to...

Microsoft Offers $30,000 Bounties for AI Security Flaws

Microsoft has launched a new bounty program that offers up to $30,000 to security...

The Human Firewall: Strengthening Your Weakest Security Link

Despite billions spent annually on cybersecurity technology, organizations continue to experience breaches with alarming...

WhatsApp Launches Advanced Privacy Tool to Secure Private Chats

WhatsApp, the world’s leading messaging platform, has unveiled a major privacy upgrade called "Advanced...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Blue Shield Exposed Health Data of 4.7 Million via Google Ads

Blue Shield of California has disclosed a significant data privacy incident affecting up to...

Microsoft Offers $30,000 Bounties for AI Security Flaws

Microsoft has launched a new bounty program that offers up to $30,000 to security...

The Human Firewall: Strengthening Your Weakest Security Link

Despite billions spent annually on cybersecurity technology, organizations continue to experience breaches with alarming...