Also known as: tracked as, Information Technology Security, CVE-2022-26134, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
Reckless Rabbit orchestrates a global investment‑scam operation that leverages Facebook advertisements to direct potential victims to fabricated news articles. These ads contain links that resolve through domains generated via RDGA techniques—random strings or recognizable English words—and are served with wildcard DNS records, effectively masking active subdomains from security scanners and allowing the actor to shuffle hosting infrastructure seamlessly. Once a user clicks, they are presented with a faux endorsement‑rich landing page that prompts the download of a seemingly legitimate PDF viewer; executing this artifact deploys custom back‑end malware designed for espionage purposes. The organization’s tactics extend beyond phishing into deeper technical exploitation. It has repeatedly abused the TeamCity server vulnerability CVE‑2023‑42793 to gain initial access in high‑profile government networks, and employs spear‑phishing emails that target key personnel via social media messaging or email vectors. Within compromised environments, they harness the Dukes credential‑dumping toolkit—including various Duke variants—to harvest local data and implant custom back‑config malware for persistence and exfiltration. Strategically, Reckless Rabbit demonstrates a focus on high‑value data acquisition across diverse sectors—government, defense, finance, media, industrial control, and healthcare. The actor’s use of country filters in DNS resolution, fake news endorsements, and multi‑platform delivery (Facebook, Telegram, email) illustrates an intent to maintain operational security while maximizing the reach of their social engineering ploys. Operationally, Reckless Rabbit shows a pattern of rapid reconfiguration: domain names are frequently changed, payloads upgraded, and new vulnerabilities leveraged as they surface. This agility hampers traditional hard‑coded detection rules and underscores the need for adaptive defenses that include behavioral analytics and threat‑intelligence feeds.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Reckless Rabbit is a highly adaptive threat actor that blends sophisticated social engineering with advanced network obfuscation to conduct investment‐scam campaigns worldwide. By leveraging Facebook advertising, fake news content, and DNS cloaking, the group deceives users into submitting personal information or installing malicious PDF tools while targeting public and private sectors across the globe. Their operations combine phishing, credential dumping, and exploitation of software vulnerabilities, reflecting a multi‑stage attack model that challenges both user awareness and network defenses.
Goals & Targeting
Reckless Rabbit aims to acquire sensitive personal and corporate information with a clear emphasis on espionage across government, defense, and critical infrastructure domains. Their investment‑scam façade amplifies credibility, enabling large‑scale social engineering while concealing the underlying technical intrusion. By exploiting public vulnerabilities such as TeamCity CVE‑2023‑42793 and embedding custom credential‑dumping tools within a cloaked command‑and‑control framework, the actor seeks to maintain long‑term access, exfiltrate valuable data, and potentially disrupt operations of high‑profile targets.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Reckless Rabbit conducts wide‑scale investment‑scam campaigns that adapt to regional regulatory and cultural norms by filtering traffic from specific countries and leveraging localized fake news anchors. Their modus operandi employs a multilayered attack chain: from the initial lure via Facebook ads and fake news to deployment of malicious PDF viewers, followed by exploitation of system vulnerabilities for deeper footholds, credential dumping, and eventual data exfiltration. The actor consistently shows an ability to rotate domains rapidly using RDGA techniques, implying significant operational tempo and resources. Victims span a broad spectrum—from defense contractors and critical‑infrastructure operators to financial services and media outlets—demonstrating the group’s broadening campaign reach over time.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis incorporates multiple publicly available reports, threat‑intel feeds, and documented vulnerabilities that point to Reckless Rabbit’s use of social engineering, DNS cloaking, and credential‑dumping tools. While the core TTPs are corroborated across several independent sources, attribution remains complicated due to overlapping aliases (e.g., MiniDionis, Patchwork) and citations of unrelated groups in some documents. Consequently, confidence is high regarding the actor’s campaign style and toolset but lower for definitive claims about specific exploitation events post‑2015. Further forensic evidence would strengthen confirmation for particular CVE usage and custom malware deployment.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
48
Tools
0
Campaigns
24
IOCs
0
Observed Data
5
Tactics