Also known as: tracked as, the Newscaster Team, Extreme' characters, Chatty Spider, Luna Moth, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
Ruthless Rabbit operates primarily through multi‑stage phishing and vishing operations that leverage fake social media profiles, spear‑phishing links, and AI‑themed lure sites to obtain initial access. Once compromised, the actor deploys a mix of remote access trojans, including RokRAT and various "Duke" families (MiniDuke, CosmicDuke, etc.), to maintain persistence, exfiltrate data rapidly, and later transition to more stealthy intrusion methods. Domain cloaking is central to Ruthless Rabbit’s infrastructure: the actor registers thousands of domains and routes them through a dedicated DNS cloaking service to obscure origin points and evade detection. The use of malicious Word documents (exploiting CVE‑2015‑1701) and embedded URLs redirects traffic through third‑party sites before delivering payloads, further complicating attribution. While the primary motivation is espionage, Ruthless Rabbit also engages in financially motivated scams—such as the “GazInvest” investment scheme that masqueraded a reputable news channel—to extract money or leverage compromised credentials for subsequent attacks. The actor’s operational breadth suggests coordination or influence from larger state‑sponsored APT programs like APT37 (North Korea) and possibly connections to the Dukes (APT29). Defense mechanisms must therefore address both spear‑phishing/vishing threats and domain cloaking, while also being prepared for rapid exfiltration followed by persistence in targeted networks.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Ruthless Rabbit is a state‑aligned threat actor using sophisticated social engineering and domain cloaking techniques to run investment‑scam campaigns while also conducting targeted espionage against a wide range of governments, defense contractors and commercial sectors worldwide.
Goals & Targeting
Ruthless Rabbit’s strategic objectives blend espionage with financial exploitation. By targeting high‑profile sectors—government, defense, finance, media, energy, telecommunications among others—the actor seeks to gather actionable intelligence and possibly leverage the acquisition of credentials for secondary operations. The use of investment scams allows the entity to financially sustain its campaigns while simultaneously seeding malware into valuable organizational networks, effectively creating a dual revenue stream of extortion and data theft.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Ruthless Rabbit employs a consistent multi‑phase campaign pattern: initial infiltration via spear‑phishing or vishing, followed by installation of remote access trojans and RMM utilities; subsequent rapid data exfiltration (“smash‑and‑grab”) enables swift target compromise. When the asset proves valuable, tactics shift to stealthy persistence using custom malware families and domain cloaking. The actor has executed high‑profile scams such as the 2022 “Channel One” GazInvest investment fraud, targeting Russian, Polish, Romanian and Kazakh users. Broader intelligence links Rustless Rabbit to North Korean APT37 through shared RMM tactics and to APT29 (Dukes) via exfiltration patterns and domain infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis draws on multiple independent reports linking Ruthless Rabbit to known APT groups and documented phishing campaigns, giving medium to high confidence regarding the actor’s tactics and tools. However, precise attribution remains uncertain due to overlapping capabilities with other state‑sponsored actors (APT37, APT29). Gap areas include detailed infrastructure mapping, definitive operational timelines, and evidence of in‑depth exfiltration objectives.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
58
Tools
0
Campaigns
24
IOCs
0
Observed Data
6
Tactics