Revolver Rabbit gang registers 500,000 domains for malware campaigns
ID: 400f72c8-314b-5a27-a8b0-e84d445d899b
STIX ID: report--400f72c8-314b-5a27-a8b0-e84d445d899b
Feed Name: Bleeping Computer
Threat Score
Infoblox researchers uncovered that the cybercriminal group "Revolver Rabbit" used registered domain generation algorithms (RDGAs) to purchase over 500,000+ domains (costing roughly $1M) to host decoy and live C2 infrastructure for XLoader infostealer variants targeting Windows and macOS; the report highlights the RDGA pattern (dictionary words + numbers with dashes), provides domain examples, and emphasizes how RDGAs conceal large-scale operations and complicate detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
