Uncovering Actor TTP Patterns and the Role of DNS in Investment Scams
This report analyzes common techniques, tactics, and procedures (TTPs) used by several investment scam actors who lure victims with fake platforms, including crypto exchanges. Key TTPs include registering large numbers of domains algorithmically, embedding similar web forms to collect user data, hiding activity through traffic distribution systems, leveraging fake news with celebrity endorsements, and sharing website structures indicative of using kits. The report focuses on two notable actors, Reckless Rabbit and Ruthless Rabbit, detailing their distinct characteristics and DNS exploitation methods. It highlights the importance of DNS in building and maintaining scam infrastructure, emphasizing the use of registered domain generation algorithms (RDGAs) and traffic distribution systems (TDSs) to strengthen resilience and evade detection.
Pulse ID: 681a2fbdb6a3c2b834cac40d
Pulse Link: https://otx.alienvault.com/pulse/681a2fbdb6a3c2b834cac40d
Pulse Author: AlienVault
Created: 2025-05-06 15:50:21
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoExchange #CyberSecurity #DNS #ICS #InfoSec #OTX #OpenThreatExchange #RAT #bot #AlienVault