Researchers Reveal Threat Actor TTP Patterns and DNS Abuse in Investment Scams
ID: b339fcdd-e6c0-5065-bdef-9b9490e0dbaf
STIX ID: report--b339fcdd-e6c0-5065-bdef-9b9490e0dbaf
Feed Name: GBHackers
Researchers uncovered sophisticated investment scam campaigns by actors such as Reckless Rabbit and Ruthless Rabbit that use Registered Domain Generation Algorithms (RDGAs), DNS abuse (wildcard responses, Traffic Distribution Systems), and cloaking to scale and evade detection. The campaigns deploy large volumes of pre-registered domains (millions observed, thousands hosted), embedded web forms to harvest personal data, geolocation-based redirection, and decoys to mislead security researchers; the report provides TTP details and example IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
