According to new Infoblox Threat Intel findings, US consumers lost $5.7 billion in investment scams in 2024.
The figure highlights how scams continue to target those seeking financial security, frequently leaving their finances endangered.
New research has identified two major threat groups contributing to the rise in scams: Reckless Rabbit and Ruthless Rabbit. Both groups rely on a technique known as registered domain generation algorithms (RDGAs) to underpin operations, creating large networks of scam websites designed to appear legitimate.
The tactics of Reckless Rabbit and Ruthless Rabbit
Reckless Rabbit
Reckless Rabbit mostly uses Facebook ads to lure victims to fraudulent investment platforms. Many ads feature fake celebrity endorsements, which contribute to helping build a false sense of credibility.
To make detection more difficult, Reckless Rabbit creates domains that return a response for any subdomain query, creating noise in the DNS system and making it harder to pinpoint which subdomains are actively being used in scams.
The group’s activities are not confined to any one region. By localising content to match the language and culture of different countries, Reckless Rabbit reaches a broader pool of potential victims.
Ruthless Rabbit
Ruthless Rabbit operates slightly differently, managing its own cloaking service to screen users before showing scam content. This makes it harder for security researchers and automated software tools to detect fraudulent sites.
Instead of depending only on ads, Ruthless Rabbit often spoofs legitimate news sites or impersonates well-known brands like WhatsApp and Meta to trick people into believing the scam platforms are legitimate.
Rogue sites also use dynamic URLs, so if one landing page is identified and blocked, a new one can quickly take its place.
Both groups have the same goal: to make their scams harder to track and faster to adapt to defensive tactics, guaranteeing that any disruption to their operations is temporary.
Chaos, trust, and opportunity for cybercriminals
According to Infoblox researchers, the scams’ success is based on two psychological factors: chaos and trust.
Economic uncertainty can drive people to seek quick financial gains, and scammers capitalise on this by creating a sense of urgency and tapping into people’s fear of missing out.
Meanwhile, trust is manufactured through the appearance of legitimacy. By using familiar logos, public figures, and professional-looking websites, scam operations become harder for users to immediately recognise as fake.
Because DNS exploitation plays a major role in the schemes, defenders can detect malicious patterns early by monitoring DNS-related UDP traffic, giving cybersecurity teams an important vantage point to combat widespread scam campaigns.
RDGAs: A new layer of complexity
RDGAs represent a change from traditional domain generation algorithms (DGAs). Instead of generating random domains and hoping they go unnoticed, RDGA actors actively register each domain they generate, creating large fleets of scam-ready websites.
The method gives cybercriminals an advantage. Even if a few domains are taken down, hundreds more remain active, making it difficult for security systems to block their operations entirely.
Infoblox Threat Intel categorises actors using this method as “rabbits” – not only for their ability to spawn new domains rapidly but also for the speed at which they adapt and expand.
Practical steps for users and organisations
Infoblox emphasised existing advice that people should be highly sceptical of investment opportunities shared through unfamiliar websites, especially if they contain celebrity endorsements. Verifying claims independently and avoiding direct links from ads can help prevent falling for scams.
Organisations can better defend their users by deploying Protective DNS services backed by threat intelligence. By blocking access to malicious domains at the DNS level, companies can stop employees or customers from inadvertently visiting scam sites.
(Photo by Unsplash)
See also: What AI says about you when you’re not in the room