Illicit cybercrime network Triad Nexus has conducted infrastructure laundering, implemented geofencing, and adopted front companies to expand fraudulent activities aimed at emerging markets after the U.S. imposed sanctions on the Philippines-based Funnull content delivery network last year, reports SecurityWeek.Despite continuously using AS152194 (CTG Server Limited) as the foundation of its operation, Triad Nexus has begun exploiting Microsoft, Google, Amazon, and Cloudflare cloud services to obtain accounts that reinforce the legitimacy of its scams, according to a Silent Push analysis. Multiple organizations, including Bank of America, MoneyGram, eBay, TripAdvisor, and Vietnam Post, also had their websites spoofed by Triad Nexus, which also moved to prohibit access from U.S.-based IP addresses to circumvent sanctions."As the network continues to withdraw from direct U.S. exposure to avoid detection, it has been pivotally expanding into the Spanish, Vietnamese, and Indonesian markets. Using localized templates to target these regions, its goal is to ensure its illicit profits continue to flow," said Silent Push researchers.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
