
Investment scams are evolving—and now, they’re everywhere on Facebook.
In the Philippines, online scams are more rampant than ever. According to the Department of Information and Communications Technology (DICT), more than ₱1 billion in online investment scam losses were reported in 2024 alone. And that’s just what made it to the authorities.
The latest wave? Highly convincing fake Facebook ads featuring celebrities, redirecting users to fraudulent investment platforms through elaborate traffic filtering systems.
How Today’s Investment Scams Work
Cybersecurity researchers recently exposed two threat groups—Reckless Rabbit and Ruthless Rabbit—that are using advanced techniques to scam users across Asia, including the Philippines.
Here’s the breakdown of their tactics:
Step 1: Facebook Ads with Fake Celebrities Scammers buy ad space on Facebook, promoting “news stories” featuring well-known personalities endorsing crypto or investment schemes.
Step 2: Redirect to Fake News Articles Clicking the ad brings users to a professionally designed fake article—often mimicking news websites—with links to register for the “opportunity.”
Step 3: Personal Info Collection via Web Forms Users are encouraged to submit their name, email, phone number, and even let the site auto-generate a password.
Step 4: Smart Filtering to Target Real Victims The scammers use tools like IP validation and traffic distribution systems (TDS) to check if the user is a real person, from a targeted country, and worth scamming.
Step 5: Direct Contact from “Investment Advisors” If a user passes all checks, they either land on a fake investment dashboard or get a call from a scammer posing as a financial representative.
These Are No Ordinary Scams
These aren’t your run-of-the-mill phishing attempts. They involve:
- Cloaking techniques to hide malicious content from security tools
- RDGA (Registered Domain Generation Algorithms) to create endless domain names
- Fake e-commerce fronts (like Amazon or Paymaya look-alikes) to avoid ad bans
- AI-generated deepfake testimonials from celebrities to build trust instantly
This is fraud at scale—and it’s working.
So How Do We Defend Against This?
Traditional email filters and antivirus tools won’t catch this. The attack doesn’t start with malware—it starts with trust. That’s where a proactive cybersecurity layer like Cyber 2.0 can help.
Cyber 2.0 isn’t just a firewall or a scanner. It’s a behavior-based security system that:
✅ Detects and blocks suspicious activity before damage spreads
✅ Prevents lateral movement once a device is compromised
✅ Operates even without frequent signature updates
✅ Complements your existing antivirus or EDR, not replaces them
In short, Cyber 2.0 focuses on what attackers do next, not just how they get in.
That makes a huge difference when social engineering is the starting point.
Final Thoughts
As investment scams grow more sophisticated—especially on platforms like Facebook—Filipino users and organizations must stay alert.
Whether you’re an IT professional or a business owner, understanding how these scams work is the first step.
The next is ensuring your network doesn’t become their next success story.
Let’s Talk, If you want to explore how Bastion Inc. can help secure your organization with proactive, modern cybersecurity like Cyber 2.0—let’s connect.
📩 Send us a message or visit www.bastion.inc for more details.
📰 Stay informed in today’s fast-moving digital world—You can join our Viber community by clicking the link or scanning the QR code below!
https://tinyurl.com/BASTIONCYBERCONNECT

References
Raywood, D. (2024, April 29). Reckless Rabbit and Ruthless Rabbit scams snare money and information. SC Media UK.
https://in.scmagazineuk.com/reckless-rabbit-and-ruthless-rabbit-scams-snare-money-and-informationWise, D., Biasca, P., & da Rocha, L. (2024, April 29). Uncovering actor TTP patterns and the role of DGA in investment scams. InfoBlox.
https://blogs.infoblox.com/threat-intelligence/uncovering-actor-ttp-patterns-and-the-role-of-dga-in-investment-scamsThe Hacker News. (2024, May 7). New investment scams use Facebook ads, RDGA domains, and IP checks to filter victims.
https://thehackernews.com/2024/05/new-investment-scams-use-facebook-ads.htmlFintechnews.ph. (2024, March 5). SEC issues warning on deepfake investment scams in Philippines.
https://fintechnews.ph/69665/security/sec-warns-of-deepfake-scams-in-philippinesPhilippine News Agency. (2024, January 31). Scam complaints triple in 2024 – DICT.
https://www.pna.gov.ph/articles/1143401






































