Morphing Meerkat is a centralized phishing-as-a-service operation active since at least 2020 that generates and operates phishing kits focused on stealing email account credentials. The actor is notable for dynamically tailoring fake login pages to a victim’s email provider by querying DNS MX records, allowing the kit to present provider-specific webmail lures or fall back to generic webmail themes when a provider is not recognized. The operation has spoofed more than 100 brands and maintains a large library of phishing page templates, including impersonation of major email and productivity providers. The actor distributes phishing lures at scale through spam campaigns and uses urgent or fear-based messaging to drive clicks. Delivery and redirection commonly rely on compromised WordPress sites, fraudulent accounts on free hosting and file-sharing platforms, and abuse of open redirects on advertising technology infrastructure to evade email security controls and obscure the final phishing destination. Morphing Meerkat also localizes phishing content by automatically translating page text into multiple languages based on the victim’s browser profile and pre-fills login forms with the victim’s email address to increase credibility. Morphing Meerkat employs multiple credential collection mechanisms, including client-side email transmission, server-side scripts, remote asynchronous transfer, and messaging-platform webhook delivery. Observed kits have sent stolen credentials and related victim data through EmailJS and Telegram bot workflows. The phishing pages incorporate several defense-evasion features, such as redirecting visitors who do not meet expected conditions to legitimate login pages, forwarding victims to authentic provider sites after repeated submissions, blocking simple inspection actions, and heavily obfuscating code through layered encoding and script transformation techniques. The actor’s tradecraft indicates a mature and reusable PhaaS ecosystem with consistent tactics, techniques, and infrastructure patterns across campaigns. High-confidence reporting supports credential theft as the primary objective. No high-confidence attribution to a nation-state or specific country of origin is established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-service operator using DNS MX record lookups to dynamically tailor fake login pages impersonating many brands.
Operates a phishing-as-a-service platform conducting large-scale credential phishing campaigns. It sends spam emails, uses compromised WordPress sites and open redirects on adtech infrastructure, queries DNS MX records via DoH to dynamically serve spoofed login pages for over 100 brands, translates phishing pages into multiple languages, and exfiltrates stolen credentials via email, PHP scripts, AJAX, and Telegram.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.