Revolver Rabbit Strikes Again: How Hackers Invested $1M in Domains for XLoader Malware

Hackers are using Registered Domain Generation Algorithms (RDGAs) to automate domain name registration for their malicious activities. Infoblox Threat Intel reported that the group Revolver Rabbit registered over 500,000 domains this way, investing at least a million dollars. RDGAs allow threat actors to scale operations…

Hot Take:

Who knew that being a cybercriminal required both coding skills and a flair for domain investment? Revolver Rabbit isn’t just hacking systems; they’re practically running a startup, complete with a million-dollar domain budget. Who needs venture capital when you’ve got malware?

Key Points:

  • Revolver Rabbit uses Registered Domain Generation Algorithms (RDGAs) to register over 500,000 domains.
  • The domains are used for command and control (C2) servers and decoy sites for XLoader malware.
  • XLoader is an advanced infostealing malware targeting both Windows and macOS systems.
  • Infoblox Threat Intel reports RDGAs as a significant and underestimated threat.
  • Revolver Rabbit’s activities went unnoticed for almost a year, highlighting gaps in cybersecurity monitoring.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here