logo

Researchers Reveal Threat Actor TTP Patterns and DNS Abuse in Investment Scams

ID: b339fcdd-e6c0-5065-bdef-9b9490e0dbaf

STIX ID: report--b339fcdd-e6c0-5065-bdef-9b9490e0dbaf

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2025-04-30

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Researchers uncovered sophisticated investment scam campaigns by actors such as Reckless Rabbit and Ruthless Rabbit that use Registered Domain Generation Algorithms (RDGAs), DNS abuse (wildcard responses, Traffic Distribution Systems), and cloaking to scale and evade detection. The campaigns deploy large volumes of pre-registered domains (millions observed, thousands hosted), embedded web forms to harvest personal data, geolocation-based redirection, and decoys to mislead security researchers; the report provides TTP details and example IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.