Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ruthless Rabbit

Also known as: tracked as, the Newscaster Team, Extreme' characters, Chatty Spider, Luna Moth, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

Ruthless Rabbit operates primarily through multi‑stage phishing and vishing operations that leverage fake social media profiles, spear‑phishing links, and AI‑themed lure sites to obtain initial access. Once compromised, the actor deploys a mix of remote access trojans, including RokRAT and various "Duke" families (MiniDuke, CosmicDuke, etc.), to maintain persistence, exfiltrate data rapidly, and later transition to more stealthy intrusion methods. Domain cloaking is central to Ruthless Rabbit’s infrastructure: the actor registers thousands of domains and routes them through a dedicated DNS cloaking service to obscure origin points and evade detection. The use of malicious Word documents (exploiting CVE‑2015‑1701) and embedded URLs redirects traffic through third‑party sites before delivering payloads, further complicating attribution. While the primary motivation is espionage, Ruthless Rabbit also engages in financially motivated scams—such as the “GazInvest” investment scheme that masqueraded a reputable news channel—to extract money or leverage compromised credentials for subsequent attacks. The actor’s operational breadth suggests coordination or influence from larger state‑sponsored APT programs like APT37 (North Korea) and possibly connections to the Dukes (APT29). Defense mechanisms must therefore address both spear‑phishing/vishing threats and domain cloaking, while also being prepared for rapid exfiltration followed by persistence in targeted networks.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Media
Energy
Telecommunications
Aerospace
Education
Manufacturing
Information technology
Maritime
Think tank
Healthcare
Pharmaceutical
Utilities
Nuclear
Chemical
Mining
Hospitality
Legal services
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
IR
KR
TW
RU
SA
CA
TR
FR
AU
IL
KZ
PK
SG
VN
UA
PL
ES
RO
AE
NL
BR
IQ
BY
AZ
IT
SY
MX
KP
EG

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 2 days ago

Executive Summary

Ruthless Rabbit is a state‑aligned threat actor using sophisticated social engineering and domain cloaking techniques to run investment‑scam campaigns while also conducting targeted espionage against a wide range of governments, defense contractors and commercial sectors worldwide.

Goals & Targeting

Ruthless Rabbit’s strategic objectives blend espionage with financial exploitation. By targeting high‑profile sectors—government, defense, finance, media, energy, telecommunications among others—the actor seeks to gather actionable intelligence and possibly leverage the acquisition of credentials for secondary operations. The use of investment scams allows the entity to financially sustain its campaigns while simultaneously seeding malware into valuable organizational networks, effectively creating a dual revenue stream of extortion and data theft.

Enhanced Description

Key Capabilities

  • DNS cloaking for domain obfuscation
  • Social engineering through forged Facebook accounts and spear‑phishing links
  • Malicious attachments and link delivery via Microsoft Word CVE exploitation
  • Voice‑phishing (vishing) pretexts to gain initial access
  • Deployment of remote access trojans such as RokRAT via email or RMM utilities
  • Utilization of custom "Duke" malware families for data exfiltration and persistence
  • Rapid “smash‑and‑grab” exfiltration followed by stealthy persistence
  • Traffic monetization infrastructure post‑phishing compromise
  • AI‑themed lure websites and counterfeit platforms (e.g., klingaimedia.com)
  • Watering hole attacks on legitimate sites

MITRE ATT&CK Tactics

Command and Control
Initial Access
Credential Access
Execution
Persistence
Exfiltration
Privilege Escalation
Collection

ATT&CK Techniques

T1071.003
T1566.001
T1566.002
T1204
T1204.002
T1193
T1189
T1021
T1068

Software / Tooling

Ghost RAT
Nefilim
SUNBURST
Brute Ratel C4
RokRAT
Noodlophile
IRONHALO
ELMER
MiniDuke
CosmicDuke
OnionDuke
CozyDuke
CloudDuke
SeaDuke
HammerDuke
PinchDuke
GeminiDuke
MiniDionis
Hammertoss

Campaigns & Victims

Ruthless Rabbit employs a consistent multi‑phase campaign pattern: initial infiltration via spear‑phishing or vishing, followed by installation of remote access trojans and RMM utilities; subsequent rapid data exfiltration (“smash‑and‑grab”) enables swift target compromise. When the asset proves valuable, tactics shift to stealthy persistence using custom malware families and domain cloaking. The actor has executed high‑profile scams such as the 2022 “Channel One” GazInvest investment fraud, targeting Russian, Polish, Romanian and Kazakh users. Broader intelligence links Rustless Rabbit to North Korean APT37 through shared RMM tactics and to APT29 (Dukes) via exfiltration patterns and domain infrastructure.

IOC Patterns

  • Domain names used for DNS cloaking and spoofing
  • Fake Facebook profiles posing as public figures
  • Malicious URLs with redirects or intermediary sites
  • Compromised legitimate websites used for watering holes
  • Malicious Microsoft Word documents exploiting CVE‑2015‑1701
  • Voice‑phishing call scripts
  • Downloads of RMM utilities via screen‑sharing
  • Indicators of remote access trojan activity (RokRAT)
  • Exfiltration over command‑and‑control channel
  • Signals associated with custom Duke malware families

Recommended Actions

  • Deploy DNS monitoring and anomaly detection to identify malicious domain resolution patterns
  • Block traffic to known spoofed domains such as klingaimedia.com and klingaistudio.com via sinkholes or web filtering
  • Implement user awareness training focused on detecting fake social media accounts and pretexting attempts
  • Apply application whitelisting or sandboxing to prevent installation of unsolicited PDF viewers or other malicious binaries
  • Set up monitoring for remote access trojan activity (e.g., RokRAT) and RMM utilities
  • Enhance email/FB filtering with advanced phishing detection to mitigate spear‑phishing links
  • Educate employees on vishing and social engineering threats, including recognizing suspicious phone calls
  • Implement strict verification procedures for remote access requests and screen‑sharing sessions
  • Deploy endpoint detection and response to detect and isolate malicious Duke family malware
  • Patch systems promptly for known vulnerabilities, notably CVE‑2015‑1701 and any other applicable CVEs
  • Use web filtering to block compromised legitimate sites used in watering hole campaigns
  • Employ network segmentation and IDS/IPS to detect rapid data exfiltration attempts
  • Maintain up‑to‑date threat intelligence feeds on APT29/Dukes and similar actor toolsets
  • Update endpoint protection with signatures for known malicious DLLs, Trojans, and RAT families

Suggested Tags

investment-scam
dns-cloaking
ghost-rat
nefilim
sunburst
social-engineering
phishing
fake-facebook-accounts
remote-access-trojan
credential-theft
noodlophile
apt37
north-korea
ai-lure
vishing
spear-phishing
watering-hole
rmm-exploitation
financial-extortion
malicious-download
remote-services
apt29
dukes
government-target
state-sponsored
custom-malware
persistent-intrusion

Confidence Assessment

The analysis draws on multiple independent reports linking Ruthless Rabbit to known APT groups and documented phishing campaigns, giving medium to high confidence regarding the actor’s tactics and tools. However, precise attribution remains uncertain due to overlapping capabilities with other state‑sponsored actors (APT37, APT29). Gap areas include detailed infrastructure mapping, definitive operational timelines, and evidence of in‑depth exfiltration objectives.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. thehackernews.com — Cited by web research for: Chatty Spider
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. thehackernews.com — Cited by web research for: Global
  4. www.infoblox.com — Cited by web research for: reserved.FeedbackWebsite

Intel Summary

9

Techniques

58

Tools

0

Campaigns

24

IOCs

0

Observed Data

6

Tactics

Tags

APT
Financial Fraud
Eastern Europe
Phishing
Investment Scam
investment-scam
dns-cloaking
ghost-rat
nefilim
sunburst
social-engineering
phishing
fake-facebook-accounts
remote-access-trojan
credential-theft
noodlophile
apt37
north-korea
ai-lure
vishing
spear-phishing
watering-hole
rmm-exploitation
financial-extortion
malicious-download
remote-services
apt29
dukes
government-target
state-sponsored
custom-malware
persistent-intrusion

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.