Cybersecurity researchers have uncovered two sophisticated threat actors—codenamed Reckless Rabbit and Ruthless Rabbit—that orchestrate investment scams through fake celebrity endorsements while concealing their operations with advanced traffic distribution systems (TDSes).
## How the Scams Operate
These threat actors create fraudulent investment platforms, particularly cryptocurrency exchanges, which they promote through social media. The attack methodology follows a calculated pattern:
1. **Initial Engagement**: Reckless Rabbit creates Facebook ads leading to fake news articles featuring celebrity endorsements for investment platforms.
2. **Data Collection**: Victims are directed to web forms requesting personal information including names, phone numbers, and email addresses.
3. **Validation Process**: The scammers perform sophisticated validation checks using legitimate IP validation tools to filter out traffic from undesired countries and verify that provided contact information is authentic.
4. **Exploitation Path**: Users who pass validation are routed through a TDS to either:
– The scam investment platform where they’re persuaded to invest with promises of high returns
– A page instructing them to await a call from a “representative”
Some campaigns employ call centers to guide victims through account setup and money transfers.
## Technical Sophistication
Both groups employ advanced techniques to evade detection:
– **Registered Domain Generation Algorithms (RDGAs)**: Unlike traditional DGAs, these algorithms register domain names using secret formulas
– **Deceptive Advertising**: Facebook ads contain unrelated images and display decoy domains different from actual redirect destinations
– **Cloaking Services**: Ruthless Rabbit operates its own cloaking service (“mcraftdb.tech”) for validation checks
Reckless Rabbit has been active since at least April 2024, primarily targeting users in Russia, Romania, and Poland while excluding traffic from countries like Afghanistan and Somalia. Ruthless Rabbit has been running campaigns since November 2022, focusing on Eastern European users.
## Broader Threat Landscape
These operations are part of a growing trend. Similar schemes include:
– The “Nomani” campaign using AI-powered video testimonials
– “Mystery Box” scams proliferating via Facebook ads that trick users into recurring subscription payments
– Scam compounds in Myanmar operated by the Karen National Army (KNA), recently sanctioned by the U.S. Treasury
## Impact and Outlook
These investment scams have proven highly profitable, with UN estimates suggesting scam centers generate annual profits of approximately $40 billion. Security experts warn that these operations will continue to grow in both number and sophistication as long as they remain profitable.
As one researcher noted, “A TDS enables threat actors to strengthen their infrastructure, making it more resilient by providing the ability to hide malicious content from security researchers and bots.”
