Massive redirection to illicit websites has been conducted by the reemergent cybersecurity operation Funnull, a Philippines-based company powering romance baiting schemes across Southeast Asia, via attacks harnessing its new RingH23 toolkit to clandestinely breach content delivery network nodes and the MacCMS content management system, according to Cyber Security News.Such a campaign, which comes after Funnull was sanctioned by the U.S. Treasury's Office of Foreign Assets Control in May, was uncovered after the identification of a dubious ELF binary from a domain yet to have detections on VirusTotal, as well as an embedded domain with 1.6 billion DNS resolutions, an analysis from QiAnXin XLab researchers revealed. Funnull, also known as Fangneng CDN, was noted to have utilized a two-pronged approach in its attacks.While the first method involved the hacking of a GoEdge CDN management node and the deployment of an SSH remote command-issuing module to run the modular RingH23 toolkit, which features several components activated throughout the attack chain, the other technique entailed official maccms.la update channel poisoning for illicit PHP backdoor distribution.
Threat Intelligence
Novel RingH23 toolkit leveraged by reemergent Funnull cybercrime operation

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



