The Federal Trade Commission (FTC) reported that consumer losses to investment scams reached a staggering $5.7 billion, climbing 24% from the previous year.
Cybersecurity researchers have now uncovered sophisticated technical tactics, techniques, and procedures (TTPs) employed by organized threat actors-most notably those tracked as “Reckless Rabbit” and “Ruthless Rabbit”-who leverage advanced DNS manipulation and automation to fuel these scams at scale.
Investment scams have diversified, ranging from text-message lures and malicious social media ads to intricate fake “profit platforms,” most often purporting to be cryptocurrency investment opportunities.

These fraudulent campaigns exploit users through embedded web forms, complex validation checks, and dynamic traffic distribution systems (TDS).
The actors behind these campaigns utilize registered domain generation algorithms (RDGAs) to create and rotate large numbers of domains, outpacing the efforts of defenders and thwarting traditional blocklisting.
Embedding and Validation: Technical Steps in the Scam Chain
Both Reckless Rabbit and Ruthless Rabbit campaigns share a core methodology: the use of embedded web forms designed to extract sensitive user data (names, emails, phone numbers), which are further tailored by auto-generating passwords and formatting phone numbers to match geolocated IP addresses.

Once personal information is harvested, the scam infrastructure performs real-time validation-including checking IP geolocation, detecting duplicate or bot traffic, and measuring the frequency of registration attempts from the same IP-to filter out security researchers and non-targets.
These validation routines typically involve API calls to legitimate IP intelligence services (such as ipinfo[.]io and ipgeolocation[.]io).
Valid victims are then either redirected by a TDS to tailored scam pages or handed over to call centers for further social engineering.
Unqualified traffic is shown benign landing pages or “thank you” messages, aiding the actors’ evasion strategies.
TDS and RDGA: Scaling Evasion and Reach
Reckless Rabbit campaigns are notable for employing traffic distribution systems that dynamically redirect users based on their geolocation-sometimes even sending U.S. visitors to legitimate investment sites to avoid detection.
These TDSs collect behavioral and technical data, enabling actors to segment and optimize their victim targeting. DNS wildcards are frequently used, causing all subdomains to resolve and flooding DNS visibility with noise, again complicating defender efforts.
RDGAs are a cornerstone of these campaigns. Unlike traditional domain generation algorithms used in malware, RDGAs allow threat actors to pre-register batches of plausible, on-brand domain names-often dictionary-based or with algorithmically-generated patterns across multiple TLDs.
This tactic enables the deployment of visually consistent scam sites, frequently changing domains to bypass blacklists, and automating on-the-fly updates to logos and content that match each new domain.
Reckless Rabbit primarily distributes lures through Facebook ads mixed with benign product promotions, camouflaging scam traffic among regular marketplace content.
According to Infoblox Report, they tailor content language and landing pages based on geolocation metadata and employ DNS wildcards to obscure true operational subdomains.
Decoy ads and benign SLD (second-level domain) content further hinder detection by automated systems.
Ruthless Rabbit, meanwhile, focuses on Eastern European targets, hosting thousands of domains on dedicated IP infrastructure and using Namecheap for registration.
They operate their own cloaking and validation API services, auto-generate fake email addresses for each victim, and use campaign-specific URL paths to foil static detection methods.
Defensive evasion is further enhanced by returning HTTP 404 errors when researchers probe domains directly.
The abuse of DNS remains central to these actors’ operational resilience. By leveraging RDGAs, TDSs, wildcard DNS, and dynamic infrastructure, threat actors consistently outmaneuver conventional remediation efforts.
Automated threat intelligence and DNS-focused analysis are thus essential tools for uncovering, correlating, and mitigating these evolving scam campaigns at scale.
Indicators of Compromise (IOCs)
| Domain / Indicator | Note |
|---|---|
| middle.sturdypants[.]com | Reckless Rabbit domain |
| brilliantwallaby[.]info | Reckless Rabbit domain |
| upkeep-vocal[.]com | Reckless Rabbit domain |
| extra-largewrinkles[.]info | Reckless Rabbit domain |
| roomyspeedboat[.]info | Reckless Rabbit domain |
| kcfebdrill[.]info | Reckless Rabbit RDGA pattern |
| almarsilk[.]info | Reckless Rabbit RDGA pattern |
| qpdecbid[.]info | Reckless Rabbit RDGA pattern |
| bortjob[.]pro | Ruthless Rabbit RDGA pattern |
| topsmot[.]pro | Ruthless Rabbit RDGA pattern |
| goaljob[.]pro | Ruthless Rabbit RDGA pattern |
| wasakot[.]pro | Ruthless Rabbit RDGA pattern |
| brudamot[.]pro | Ruthless Rabbit SLD (GazInvest campaign) |
| kinabik[.]pro | Ruthless Rabbit SLD (Russian news spoof) |
| bitcoin-apex[.]guru | Automated RDGA investment scam domain |
| bitcoinapex-platform[.]click | Automated RDGA investment scam domain |
| vensotixapp-platform[.]store | Automated RDGA investment scam domain |
| vasezonixapp[.]guru | Automated RDGA investment scam domain |
| aportunex[.]app | Automated RDGA investment scam domain |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates