Revolver Rabbit is a scam-focused threat cluster associated with online investment fraud delivered through social-media advertising and traffic distribution systems. The name appears alongside other scam-related actor designations, but high-confidence public detail about Revolver Rabbit itself is currently limited. Available reporting places it in the same general ecosystem as actors that use cloaking, redirect chains, and deceptive advertising to steer victims toward fraudulent investment or cryptocurrency-themed platforms while obscuring malicious infrastructure from researchers and automated enforcement systems. Based on the currently available information, there is insufficient high-confidence evidence to attribute a specific country of origin, victim geography, industry focus, operational sub-groups, or a fuller set of tactics uniquely to Revolver Rabbit beyond its association with this broader scam infrastructure and traffic-routing tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.