Reckless Rabbit is an investment-fraud threat cluster focused on social-media-driven scam operations that funnel victims into bogus investment platforms, including fake cryptocurrency trading services. The activity has been observed since at least April 2024. It relies on Facebook advertising that impersonates news content and uses spoofed celebrity endorsements to attract users. Victims are typically sent to fake news-style landing pages and then to registration forms that collect personal information before being routed onward. A defining feature of Reckless Rabbit is its use of traffic distribution and validation workflows to filter victims and conceal malicious infrastructure. The operation checks user geography and validates submitted contact details before deciding whether to advance a target to the scam platform or to a follow-up workflow involving human operators. Some victims are directed to wait for contact from a representative, indicating integration with call-center-enabled fraud. Users who do not meet targeting criteria may be shown benign or dead-end pages. The cluster also uses a registered domain generation approach to create and rotate scam infrastructure at scale. Its operators employ ad-evasion and cloaking tactics, including mixing fraudulent advertisements with benign marketplace-style content and displaying decoy branding or domains that differ from the actual redirect destination. These methods increase resilience, complicate detection, and reduce exposure to automated analysis. Known related activity includes another cluster tracked separately as Ruthless Rabbit, which uses similar investment-scam tradecraft, but Reckless Rabbit is distinguished by its own targeting and infrastructure patterns. Reckless Rabbit is best characterized as a financially motivated cyber-enabled fraud actor specializing in social-media lures, victim qualification, and conversion of selected targets into investment scam pipelines.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Investment-scam activity cluster using spoofed celebrity endorsements, traffic distribution systems, and victim filtering (e.g., IP checks).
Runs fraudulent investment/crypto scams promoted via social-media malvertising (notably Facebook) using spoofed celebrity endorsements and fake news articles. Uses embedded web forms to harvest victim PII, performs validation (geo/IP and data authenticity checks), and then routes qualified victims through a traffic distribution system (TDS) to scam platforms; uses a registered domain generation algorithm (RDGA) to stand up scam domains and employs ad/URL decoys to evade enforcement.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.