Connect with us
European Gaming Congress 2024

Artificial Intelligence

Infoblox Threat Intel Discovers Muddling Meerkat, a DNS Operation Controlling China’s Great Firewall

Published

on

infoblox-threat-intel-discovers-muddling-meerkat,-a-dns-operation-controlling-china’s-great-firewall

Muddling Meerkat utilizes sophisticated DNS activities, likely propagated by Chinese state actors, to bypass traditional security measures and probe networks worldwideWith market-leading DNS expertise, backed by data science and AI, Infoblox Threat Intel hunts, tracks and stops threats lurking in DNS, up to 60+ days before other security toolsInfoblox Threat Intel enables Infoblox BloxOne® Threat Defense customers to see who and what connects to their network – disrupting threat actors’ operations and infrastructure pre-incidentInfoblox introduces Zero Day DNS™ feature that detects and blocks attacks launched from domains immediately used after registration as part of a zero trust model for DNSSANTA CLARA, Calif., April 29, 2024 /PRNewswire/ — Infoblox Inc., a leader in cloud networking and security services, today announced that its threat intel researchers, in collaboration with external researchers, have uncovered “Muddling Meerkat,” a likely PRC state actor with the ability to control the Great Firewall (GFW) of China, a system that censors and manipulates traffic entering and exiting China’s internet. This DNS threat actor is particularly sophisticated in its ability to bypass traditional security measures, as it conducts operations by creating large volumes of widely distributed DNS queries that are subsequently propagated through the internet through open DNS resolvers. Infoblox leveraged its deep understanding and unique access to DNS to discover this cyberthreat, pre-incident, blocking its domains to ensure its customers are safe.

“Infoblox Threat Intel eats, sleeps, and breathes DNS data,” said Dr. Renée Burton, Vice President, Infoblox Threat Intel. “Our unrelenting focus on DNS, using cutting-edge data science and AI, has enabled our global team of threat hunters to be the first to discover Muddling Meerkat lurking in the shadows and produce critical threat intelligence for our customers. This actor’s complex operations demonstrates a strong understanding of DNS, stressing the importance of having a DNS detection and response (DNSDR) strategy in place to stop sophisticated threats like Muddling Meerkat.”
The moniker “Muddling Meerkat” was given to describe the actor as an animal that appears cute, but in reality it can be dangerous, living in a complex network of burrows underground, and out of view. From a technical perspective, “Meerkat” references the abuse of open resolvers, particularly through the use of DNS mail exchange (MX) records. “Muddling” refers to the bewildering nature of their operations.
With a deep understanding of and visibility into DNS, Infoblox Threat Intel can see attacker infrastructure as it’s created, stopping both known and emerging threats earlier. With 46M unique threat indicators detected in 2023 and a practically non-existent false positive rate of 0.0002%, Infoblox Threat Intel detected 82% of threats before or at the first query thus far in 2024 leveraging our patent pending threat intelligence system along with Infoblox’s new Zero Day DNS capability. The threat actor, Muddling Meerkat, has been operating covertly since at least October 2019. At first glance, its operations look like Slow Drip distributed denial-of-service (DDoS) attacks, however, it is unlikely DDoS is their ultimate goal. The motivation of the actor is unknown, though they may be performing reconnaissance or prepositioning for future attacks.
Muddling Meerkat demonstrates a sophisticated understanding of DNS that is uncommon among threat actors today – clearly pointing out that DNS is a powerful weapon leveraged by adversaries.
The research further shows that their operations:
Induce responses from the Great Firewall, including false MX records from the Chinese IP address space. This highlights a novel use of national infrastructure as a fundamental part of their strategy.Trigger DNS queries for MX and other record types to domains not owned by the actor, but which reside under well-known top-level domains such as .com and .org. This tactic highlights the use of distraction and obfuscation techniques to hide the real intended purpose.Utilize super-aged domains, typically registered prior to the year 2000, enabling the actor to blend in with other DNS traffic and avoid detection. This further highlights the threat actor’s understanding of both DNS and existing security controls.The full report on Muddling Meerkat can be found here.
Infoblox Threat Intel Gets a Bold New Look, Demonstrating Industry-Leading Commitment to DNS Threat Intelligence
Infoblox Threat Intel is the leading creator of original DNS threat intelligence in the market today. The group, led by Dr. Renée Burton, a 22-year veteran of NSA, is composed of researchers across five countries who have deep expertise in DNS, data science, ML/AI, intelligence analysis, software reverse engineering, and malicious spam detection. Infoblox put a new focus on the team’s public identity to distinguish itself from the sea of threat intel aggregators – highlighting its expertise in original DNS threat research.
Throughout the past year, Infoblox Threat Intel was the first to report other DNS threat actors, all of which had gone undetected for over a year by the rest of the industry. These include DNS C2 malware toolkit Decoy Dog, malicious link shortening service provider Prolific Puma, the most extensive known cybercriminal traffic distribution system VexTrio Viper (aka VexTrio), and DNS CNAME redirection network provider Savvy Seahorse. These publications represent a small fraction of the number of DNS threat actors Infoblox Threat Intel has discovered and are tracking.
“The sheer mass of threat actors effectively hiding in the DNS should be a wakeup call for every defender to make DNS threat intelligence an essential part of their strategy,” added Burton. “Why? Because more than 92%2 of malware utilizes DNS.”
The most effective way to protect against these sophisticated threats is with DNS Detection and Response systems like Infoblox’s BloxOne® Threat Defense. Unlike other security solutions that are malware and post-event centric, Infoblox Threat Intel uses a multi-pronged approach to discover threats in DNS.
Introducing Zero Day DNS, the Newest Feature within BloxOne Threat Defense
Infoblox’s new cloud-based Zero Day DNS™ augments the existing methods to detect and block possible threats from domains that are registered by threat actors just minutes to hours before being used in an attack. It is a zero trust model for DNS that leverages the extensive visibility Infoblox has to rapidly adjudicate hundreds of thousands of new domains in near real time every day.
While most domains are aged before they are used by attackers, Infoblox has discovered an alarming trend over the last 18 months, where threat actors register lookalike domains and immediately use them in targeted attacks. Zero Day DNS was designed specifically to address this risk.
Zero Day DNS is tailored to individual customer networks, providing a new form of custom threat intel for Infoblox BloxOne Threat Defense Advanced Cloud customers. This capability provides the earliest defense against spearphishing attacks, which were responsible for 66% of all data breaches in 2023 according to Barracuda Networks annual report on phishing trends.1 Initial results show that Zero Day DNS can detect novel threats without risk of blocking vital network access. Over 16% of the flagged domains were deemed malicious within 48 hours by other analytics.
“Zero Day DNS is not just a nice to have, but a strategic advantage in an environment where threat actors, particularly ransomware actors, are using a domain immediately after registration for spearphishing,” added Burton.
Meet Infoblox Threat Intel
Dr. Burton will discuss Muddling Meerkat at the RSA Conference in San Francisco, May 6-9. Live sessions will be held at Booth S-726. Visit this here to request a meeting with Infoblox at RSAC 2024.
Additionally, Dr. Burton is hosting a webinar titled: Infoblox Threat Intel – Disrupting Cybercrime Where it Begins – DNS, on May 8 at 10 am PDT. Register to attend here.
About InfobloxInfoblox unites networking and security to deliver unmatched performance and protection. Trusted by Fortune 100 companies and emerging innovators, we provide real-time visibility and control over who and what connects to your network, so your organization runs faster and stops threats earlier. Visit Infoblox.com, or follow-us on LinkedIn or Twitter.
Media Contacts:[email protected]@ruderfinn.com 
1 https://www.barracuda.com/reports/spear-phishing-trends-20232 https://executivegov.com/2020/06/anne-neuberger-on-nsas-secure-dns-pilot-program/
 
 
Photo – https://mma.prnewswire.com/media/2396885/Infoblox_Threat_Intel_Logo.jpgPhoto – https://mma.prnewswire.com/media/2396887/INFOBLOX_Threat_Intel.jpgPhoto – https://mma.prnewswire.com/media/2396886/Infoblox_Threat_Intel_picture_2.jpgPhoto – https://mma.prnewswire.com/media/2397110/Threat_Intel_image_5.jpg

View original content:https://www.prnewswire.co.uk/news-releases/infoblox-threat-intel-discovers-muddling-meerkat-a-dns-operation-controlling-chinas-great-firewall-302129799.html

Continue Reading
Advertisement

Artificial Intelligence

Eye Level holds its 2024 Eye Level Math Olympiad for students to test out their math skills.

Published

on

eye-level-holds-its-2024-eye-level-math-olympiad-for-students-to-test-out-their-math-skills.

SEOUL, South Korea, Oct. 17, 2024 /PRNewswire/ — Eye Level is hosting the 2024 Math Olympiad (ELMO 2024), inviting students from grades 1 to 8 worldwide to showcase their math skills. The competition will run from November 9 to December 1, following each country’s schedule across 15 countries.object

This Olympiad, part of the annual Eye Level Math Olympiad series established in 2004, offers students a valuable opportunity to assess and enhance their mathematical abilities. The test lasts approximately one hour and is designed to challenge students across various areas of math skills, covering most arithmetic and critical thinking domains. Questions are tailored to each grade level, allowing students to evaluate their skills objectively.All participants will receive a certificate of participation and a comprehensive analysis of their test results. Official results and winners will be announced in January 2025 on myeyelevel.com, with award ceremonies planned to be held locally for outstanding participants.
Registration is currently open on myeyelevel.com.
About Eye Level
Eye Level is an international provider of supplemental education services in Math and English with more than 2 million students having experienced its programs. Eye Level guides the students to learn at their own pace, and achieve their goals. With a growth-minded learning process, Eye Level helps students build good learning habits that become the foundation of great talent – setting them up for success in school and beyond. 
Photo – https://mma.prnewswire.com/media/2533165/p14_1_ELMO.jpg

View original content:https://www.prnewswire.co.uk/news-releases/eye-level-holds-its-2024-eye-level-math-olympiad-for-students-to-test-out-their-math-skills-302278994.html

Continue Reading

Artificial Intelligence

n2 Group Advances HPC/AI Portfolio by Acquiring Managed Services Company X-ISS

Published

on

n2-group-advances-hpc/ai-portfolio-by-acquiring-managed-services-company-x-iss

OXFORD, England, Oct. 17, 2024 /PRNewswire/ — n2 Group, the transformative computing technology investment company, announces the acquisition of high-performance computing (HPC) and AI specialists, X-ISS. The addition of X-ISS expands the Group’s portfolio– joining NAG, VSNi, BioTeam and STAC—as it accelerates advancements in technology and computation, underpinned by innovation, technical excellence, and a focus on long-term growth.

n2 Group invests selectively in technical computing companies with deep business impact in a variety of sectors, providing operational support and a collaborative approach to innovation and business transformation. The addition of X-ISS will further strengthen the Group’s already strong HPC/AI credentials, with NAG, STAC and BioTeam already adding to this space. 
X-ISS is a pioneer in Managed Services specifically designed for HPC/AI. With their in-depth understanding of hardware and software complexities within HPC and AI, they deliver highly impactful end-to-end services to clients through the integration, optimization and management of HPC/AI systems. The integration of X-ISS into n2 Group aligns with the Group vision of improving the accessibility, quality and robustness of computing solutions to enable greater productivity in industry. 
X-ISS will operate as an autonomous business within the n2 Group, maintaining its brand, identity and ethos. n2 Group’s status as an independent, member-backed organisation with no external financial stakeholders allows X-ISS to continue providing impartial advice based on the technology needs and challenges of its clients. Inter-group synergies will enable greater innovation and collaboration, advancing the Group’s position and long-term HPC/AI market impact. 
“X-ISS strengthens the n2 community in the strategically important area of HPC/AI”, said Adrian Scales, Snr Director of Investments and Partnerships at n2 Group. “As a respected boutique HPC service provider, X-ISS is helping clients navigate an increasingly complex landscape in terms of technologies and software integrations with AI and analytics. The acquisition strongly complements the Group’s existing HPC professional services capability, and we are delighted to have them on board.”
“This is an important milestone for X-ISS.”, said Deepak Khosla, CEO X-ISS, “The partnership with n2 Group will enable us to enhance our flagship ManagedHPC solution by leveraging n2’s complementary services and product developments, allowing us to deliver even greater value to our customers. As businesses face increasing challenges with complex technologies like AI and cloud computing, we’re now better equipped to support them with the same quality, passion, and partnership that defines X-ISS. I am excited about the opportunities this can bring for current and future X-ISS customers.”
About n2 Group  
At n2 Group we are transforming computing and technology investment with a radical new approach. Our businesses are all established, purpose-driven market-leaders in computing products or services. We stimulate long-term sustainable growth through group-level support in strategy, business development, innovation, and operations. With no shareholders or external financial interests, we reinvest all profits back into the group or to the community, reinforcing our commitment to positive social impact through technological advancements.    
n2 Group companies are at the forefront of computing and IT infrastructure, helping clients in various sectors to be more productive, innovative or reduce risk through advanced software and services. Rapidly expanding in high-performance computing, artificial intelligence, and scientific computing, our businesses maintain their unique brands and identities, but benefit from the expanded network available through the group.   
n2 Group Companies  
•  BioTeam: Scientific computing consultancy integrating technologies, data, and cultures to accelerate science. 
•  NAG: Advanced products and services in algorithms, optimization, high-performance computing and AI. 
•  STAC: Independent financial services technology research and community events. 
•  VSNi: Proven statistical solutions and data expertise driving innovation and success.  
•  X-ISS: Industry leading management and analytics solutions for HPC/AI systems.
For more detailed information and the latest updates, visit n2 Group. 
Logo – https://mma.prnewswire.com/media/2271328/n2_Group_Logo.jpgLogo –  https://mma.prnewswire.com/media/2533549/XISS_Logo.jpg
 

View original content:https://www.prnewswire.co.uk/news-releases/n2-group-advances-hpcai-portfolio-by-acquiring-managed-services-company-x-iss-302279433.html

Continue Reading

Artificial Intelligence

TIE 2024 Unveils a New Era of Innovation

Published

on

tie-2024-unveils-a-new-era-of-innovation

A New Era of AI-powered Innovation and Industrial Revolution: Driving Integration of Smart Tech into Daily Life.
TAIPEI, Oct. 17, 2024 /PRNewswire/ — The 2024 Taiwan Innotech Expo (TIE) kicked off today at Taipei World Trade Center with a focus on “Smart Tech Island –The New Era of AI.” This year’s event showcases over a thousand advanced technologies and research achievements across six key areas: digital information, data security, precision health, defense, green and renewable energy, and civil and military resilience, heralding a new chapter in the technological evolution of industries.

Online and On-Site Exhibitions Offers Comprehensive Access to the Latest Innovations
TIE 2024 offers a seamless blend of virtual and physical experiences. Visitors can explore technologies, register for events, and plan their visit online before the expo opens. During the expo period, the event website provides essential tools such as e-meeting requests, product maps, and program registration. For those who were unable to attend in person, online attendees can view exhibits and access business negotiation records even after the expo is closed, fostering ongoing collaboration and opportunities. As a leading platform for technological innovation exchanges in Taiwan, TIE 2024 showcases the nation’s advancements in AI and smart technologies. This event is anticipated to drive industry transformation and opens new chapters in technological innovation.
Official Website: https://tie.twtm.com.tw/en

View original content:https://www.prnewswire.co.uk/news-releases/tie-2024-unveils-a-new-era-of-innovation-302279310.html

Continue Reading
Advertisement
Advertisement

Latest News

Trending