Researchers Expose Threat Actor TTPs and DNS Manipulation Behind Investment Scams

The Federal Trade Commission (FTC) reported that consumer losses to investment scams reached a staggering $5.7 billion, climbing 24% from the previous year.

Cybersecurity researchers have now uncovered sophisticated technical tactics, techniques, and procedures (TTPs) employed by organized threat actors-most notably those tracked as “Reckless Rabbit” and “Ruthless Rabbit”-who leverage advanced DNS manipulation and automation to fuel these scams at scale.

Investment scams have diversified, ranging from text-message lures and malicious social media ads to intricate fake “profit platforms,” most often purporting to be cryptocurrency investment opportunities.

Investment Scams
Example of embedded web form in a February 2025 investment scam

These fraudulent campaigns exploit users through embedded web forms, complex validation checks, and dynamic traffic distribution systems (TDS).

The actors behind these campaigns utilize registered domain generation algorithms (RDGAs) to create and rotate large numbers of domains, outpacing the efforts of defenders and thwarting traditional blocklisting.

Embedding and Validation: Technical Steps in the Scam Chain

Both Reckless Rabbit and Ruthless Rabbit campaigns share a core methodology: the use of embedded web forms designed to extract sensitive user data (names, emails, phone numbers), which are further tailored by auto-generating passwords and formatting phone numbers to match geolocated IP addresses.

Investment Scams
Reckless Rabbit’s Facebook ads for products on Amazon

Once personal information is harvested, the scam infrastructure performs real-time validation-including checking IP geolocation, detecting duplicate or bot traffic, and measuring the frequency of registration attempts from the same IP-to filter out security researchers and non-targets.

These validation routines typically involve API calls to legitimate IP intelligence services (such as ipinfo[.]io and ipgeolocation[.]io).

Valid victims are then either redirected by a TDS to tailored scam pages or handed over to call centers for further social engineering.

Unqualified traffic is shown benign landing pages or “thank you” messages, aiding the actors’ evasion strategies.

TDS and RDGA: Scaling Evasion and Reach

Reckless Rabbit campaigns are notable for employing traffic distribution systems that dynamically redirect users based on their geolocation-sometimes even sending U.S. visitors to legitimate investment sites to avoid detection.

These TDSs collect behavioral and technical data, enabling actors to segment and optimize their victim targeting. DNS wildcards are frequently used, causing all subdomains to resolve and flooding DNS visibility with noise, again complicating defender efforts.

RDGAs are a cornerstone of these campaigns. Unlike traditional domain generation algorithms used in malware, RDGAs allow threat actors to pre-register batches of plausible, on-brand domain names-often dictionary-based or with algorithmically-generated patterns across multiple TLDs.

This tactic enables the deployment of visually consistent scam sites, frequently changing domains to bypass blacklists, and automating on-the-fly updates to logos and content that match each new domain.

Reckless Rabbit primarily distributes lures through Facebook ads mixed with benign product promotions, camouflaging scam traffic among regular marketplace content.

According to Infoblox Report, they tailor content language and landing pages based on geolocation metadata and employ DNS wildcards to obscure true operational subdomains.

Decoy ads and benign SLD (second-level domain) content further hinder detection by automated systems.

Ruthless Rabbit, meanwhile, focuses on Eastern European targets, hosting thousands of domains on dedicated IP infrastructure and using Namecheap for registration.

They operate their own cloaking and validation API services, auto-generate fake email addresses for each victim, and use campaign-specific URL paths to foil static detection methods.

Defensive evasion is further enhanced by returning HTTP 404 errors when researchers probe domains directly.

The abuse of DNS remains central to these actors’ operational resilience. By leveraging RDGAs, TDSs, wildcard DNS, and dynamic infrastructure, threat actors consistently outmaneuver conventional remediation efforts.

Automated threat intelligence and DNS-focused analysis are thus essential tools for uncovering, correlating, and mitigating these evolving scam campaigns at scale.

Indicators of Compromise (IOCs)

Domain / IndicatorNote
middle.sturdypants[.]comReckless Rabbit domain
brilliantwallaby[.]infoReckless Rabbit domain
upkeep-vocal[.]comReckless Rabbit domain
extra-largewrinkles[.]infoReckless Rabbit domain
roomyspeedboat[.]infoReckless Rabbit domain
kcfebdrill[.]infoReckless Rabbit RDGA pattern
almarsilk[.]infoReckless Rabbit RDGA pattern
qpdecbid[.]infoReckless Rabbit RDGA pattern
bortjob[.]proRuthless Rabbit RDGA pattern
topsmot[.]proRuthless Rabbit RDGA pattern
goaljob[.]proRuthless Rabbit RDGA pattern
wasakot[.]proRuthless Rabbit RDGA pattern
brudamot[.]proRuthless Rabbit SLD (GazInvest campaign)
kinabik[.]proRuthless Rabbit SLD (Russian news spoof)
bitcoin-apex[.]guruAutomated RDGA investment scam domain
bitcoinapex-platform[.]clickAutomated RDGA investment scam domain
vensotixapp-platform[.]storeAutomated RDGA investment scam domain
vasezonixapp[.]guruAutomated RDGA investment scam domain
aportunex[.]appAutomated RDGA investment scam domain

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories