logo

Uncovering Actor TTP Patterns and the Role of DNS in Investment Scams

ID: c9a3bae7-71df-5c7a-912b-1eafd7be1c69

STIX ID: report--c9a3bae7-71df-5c7a-912b-1eafd7be1c69

Feed Name: Infoblox Threat Intel Blog

Threat Score
70/100

Date Published: 2025-04-28

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report analyzes large-scale investment scam campaigns that use fake ‘profit platforms’ and social-media ads to harvest victims’ personal and financial information; it profiles two actors (Reckless Rabbit and Ruthless Rabbit), describes their techniques—registered domain generation algorithms (RDGAs), traffic distribution systems (TDS), cloaking/validation APIs, wildcard DNS and decoy pages—and provides domain/IP/URL indicators and behavioral patterns to help detect and block the infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.