Spoofing emails are a common tactic among threat actors to make emails appear legitimate.Infoblox Threat Intel discovered a group named Muddling Meerkat conducting DNS operations in China.The threat actors behind Muddling Meerkat used domain spoofing to evade security safeguards.Infoblox Threat Intel used home-grown telemetry and community feedback to investigate Muddling Meerkat.QR code phishing campaigns were the largest group of malspam that targeted Chinese email recipients.Japanese phishing campaigns were another sizable percentage of collected spam that targeted Japanese users.Domain spoofing, fake domains, and TDSs were used to evade detection by these Chinese actors.Extortion emails are still common, and they contain domain spoofing to make them appear more legitimate.Mysterious Malspam is a spam campaign with spoofed sender domains and benign Excel spreadsheet attachments.Domain spoofing is a widely used tactic among threat actors to evade security safeguards.