Public Domain Name System (DNS) resolvers inadvertently reveal cache state via non-recursive (RD=0) queries. This enables the inference of a privacy-preserving lower bound on the number of users who have queried a domain by analyzing Time-to-Live (TTL) values across multiple probes. Prior work has examined DNS cache snooping manually, typically at a single scale and primarily for measurement. In this workshop paper, we present MudHunter, a centrally orchestrated, Internet-scale tool that automates DNS cache snooping to generate actionable Cyber Threat Intelligence (CTI). We developed custom tooling using the CAIDA Scamper library to coordinate 130 globally distributed CAIDA Ark vantage points for running parallel DNS lookups, thereby transcending methods that require per-node deployments. Using MudHunter we conduct our parallel measurements on the 4 popular public DNS providers, namely, Google Public DNS, Cloudflare, Quad9, and OpenDNS. We use MudHunter to detect the caching architecture of the 4 public resolvers across their PoPs around the world, interestingly, our study uncovers fresh details about the updated cache architecture of the resolvers we analyze, which appears not to have been systematically examined since 2020. Furthermore, we demonstrate MudHunter’s practical cybersecurity value through two week-long case studies to track illicit domains pertained to (i) botnet C2 infrastructure and (ii) banking phishing campaigns. Our MudHunter domain activity estimation provide conservative lower bounds on global threat exposure. Across both case studies, for a given domain, domain activity estimations peaks in a small set of regions while most vantage points remain near zero, indicating regionally targeted, short-lived activity rather than uniform global spread. This turns cache observations into actionable, privacy-preserving threat intelligence: timely, geographically resolved signals that drive triage, blocking, and takedown.