Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Reckless Rabbit

Also known as: tracked as, Information Technology Security, CVE-2022-26134, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

Reckless Rabbit orchestrates a global investment‑scam operation that leverages Facebook advertisements to direct potential victims to fabricated news articles. These ads contain links that resolve through domains generated via RDGA techniques—random strings or recognizable English words—and are served with wildcard DNS records, effectively masking active subdomains from security scanners and allowing the actor to shuffle hosting infrastructure seamlessly. Once a user clicks, they are presented with a faux endorsement‑rich landing page that prompts the download of a seemingly legitimate PDF viewer; executing this artifact deploys custom back‑end malware designed for espionage purposes. The organization’s tactics extend beyond phishing into deeper technical exploitation. It has repeatedly abused the TeamCity server vulnerability CVE‑2023‑42793 to gain initial access in high‑profile government networks, and employs spear‑phishing emails that target key personnel via social media messaging or email vectors. Within compromised environments, they harness the Dukes credential‑dumping toolkit—including various Duke variants—to harvest local data and implant custom back‑config malware for persistence and exfiltration. Strategically, Reckless Rabbit demonstrates a focus on high‑value data acquisition across diverse sectors—government, defense, finance, media, industrial control, and healthcare. The actor’s use of country filters in DNS resolution, fake news endorsements, and multi‑platform delivery (Facebook, Telegram, email) illustrates an intent to maintain operational security while maximizing the reach of their social engineering ploys. Operationally, Reckless Rabbit shows a pattern of rapid reconfiguration: domain names are frequently changed, payloads upgraded, and new vulnerabilities leveraged as they surface. This agility hampers traditional hard‑coded detection rules and underscores the need for adaptive defenses that include behavioral analytics and threat‑intelligence feeds.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Media
Energy
Telecommunications
Aerospace
Education
Information technology
Maritime
Manufacturing
Think tank
Healthcare
Pharmaceutical
Critical infrastructure
Nuclear
Chemical
Mining
Utilities
Hospitality
Legal services
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
TW
RU
SA
CA
TR
FR
AU
IL
KZ
PK
SG
VN
UA
PL
ES
RO
AE
NL
BR
IQ
BY
AZ
IT
SY
MX
KP
EG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Reckless Rabbit is a highly adaptive threat actor that blends sophisticated social engineering with advanced network obfuscation to conduct investment‐scam campaigns worldwide. By leveraging Facebook advertising, fake news content, and DNS cloaking, the group deceives users into submitting personal information or installing malicious PDF tools while targeting public and private sectors across the globe. Their operations combine phishing, credential dumping, and exploitation of software vulnerabilities, reflecting a multi‑stage attack model that challenges both user awareness and network defenses.

Goals & Targeting

Reckless Rabbit aims to acquire sensitive personal and corporate information with a clear emphasis on espionage across government, defense, and critical infrastructure domains. Their investment‑scam façade amplifies credibility, enabling large‑scale social engineering while concealing the underlying technical intrusion. By exploiting public vulnerabilities such as TeamCity CVE‑2023‑42793 and embedding custom credential‑dumping tools within a cloaked command‑and‑control framework, the actor seeks to maintain long‑term access, exfiltrate valuable data, and potentially disrupt operations of high‑profile targets.

Enhanced Description

Key Capabilities

  • Social engineering via Facebook advertising
  • DNS cloaking for domain obfuscation and C&C
  • Pretexting through social media messaging to lure victims into installing malicious PDF viewers
  • Exploitation of software vulnerabilities (e.g., TeamCity CVE‑2023‑42793)
  • Spear-phishing campaigns across email and messaging platforms
  • Watering hole attacks that redirect users to malicious landing pages
  • Credential dumping using the Dukes toolkit (MiniDuke, CosmicDuke, OnionDuke, CozyDuke, SeaDuke, CloudDuke, HammerDuke)
  • Deployment of custom back‑config malware for persistence and exfiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Credential Access

ATT&CK Techniques

T1204
T1071.004
T1027
T1190
T1566
T1189
T1003

Software / Tooling

MiniDuke
CosmicDuke
OnionDuke
CozyDuke
SeaDuke
CloudDuke
HammerDuke
BackConfig

Campaigns & Victims

Reckless Rabbit conducts wide‑scale investment‑scam campaigns that adapt to regional regulatory and cultural norms by filtering traffic from specific countries and leveraging localized fake news anchors. Their modus operandi employs a multilayered attack chain: from the initial lure via Facebook ads and fake news to deployment of malicious PDF viewers, followed by exploitation of system vulnerabilities for deeper footholds, credential dumping, and eventual data exfiltration. The actor consistently shows an ability to rotate domains rapidly using RDGA techniques, implying significant operational tempo and resources. Victims span a broad spectrum—from defense contractors and critical‑infrastructure operators to financial services and media outlets—demonstrating the group’s broadening campaign reach over time.

IOC Patterns

  • DNS cloaking (obfuscated domain resolution)
  • Fake news article URLs routed via Facebook ads
  • Malicious PDF viewer distribution via social media channels
  • CVE identifiers in exploitation campaigns
  • Spear-phishing email addresses and subject lines
  • Watering hole landing page URLs

Recommended Actions

  • Implement comprehensive user awareness training focused on social engineering, pretexting, and phishing via Facebook ads.
  • Deploy DNS monitoring tools to detect anomalous or cloaked queries and automatically block known malicious domains.
  • Enforce validation of PDF integrity through sandbox execution or hash comparison before allowing installation.
  • Block or strictly filter Facebook ad links that redirect to unfamiliar or suspicious third‑party sites.
  • Apply timely patches for critical vulnerabilities, particularly TeamCity CVE‑2023‑42793 and any legacy software referenced by the actor.
  • Strengthen email filtering and apply advanced threat detection to mitigate spear‑phishing attempts.
  • Monitor network traffic for watering hole indicators such as unusual access patterns or repeated connections to known malicious hosts.
  • Block known malicious IPs, domain suffixes, or C2 infrastructures used by back‑config malware and Dukes toolkits.
  • Implement intrusion detection/prevention signatures that flag credential dumping activity (e.g., use of lsass secrets or system utilities).

Suggested Tags

Investment Scam
DNS Cloaking
Social Engineering
Phishing via Facebook Ads
Fake News
APT
TeamCity Vulnerability
CVE‑2023‑42793
Spear Phishing
Watering Hole
Credential Dumping
BackConfig
Dukes Toolkit
Chinastrats

Confidence Assessment

The analysis incorporates multiple publicly available reports, threat‑intel feeds, and documented vulnerabilities that point to Reckless Rabbit’s use of social engineering, DNS cloaking, and credential‑dumping tools. While the core TTPs are corroborated across several independent sources, attribution remains complicated due to overlapping aliases (e.g., MiniDionis, Patchwork) and citations of unrelated groups in some documents. Consequently, confidence is high regarding the actor’s campaign style and toolset but lower for definitive claims about specific exploitation events post‑2015. Further forensic evidence would strengthen confirmation for particular CVE usage and custom malware deployment.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

Intel Summary

7

Techniques

48

Tools

0

Campaigns

24

IOCs

0

Observed Data

5

Tactics

Tags

fraud
scam
social-engineering
financial-motivation
retail-sector
individual-targeting
Investment Scam
DNS Cloaking
Social Engineering
Phishing via Facebook Ads
Fake News
APT
TeamCity Vulnerability
CVE‑2023‑42793
Spear Phishing
Watering Hole
Credential Dumping
BackConfig
Dukes Toolkit
Chinastrats

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.