Threat Intelligence

Triad Nexus cybercrime operation flourishes despite US sanctions

Hacked computer system showing a skull icon with lines of code, illustrating cybercrime, data protection issues, and malware

Illicit cybercrime network Triad Nexus has conducted infrastructure laundering, implemented geofencing, and adopted front companies to expand fraudulent activities aimed at emerging markets after the U.S. imposed sanctions on the Philippines-based Funnull content delivery network last year, reports SecurityWeek.

Despite continuously using AS152194 (CTG Server Limited) as the foundation of its operation, Triad Nexus has begun exploiting Microsoft, Google, Amazon, and Cloudflare cloud services to obtain accounts that reinforce the legitimacy of its scams, according to a Silent Push analysis. Multiple organizations, including Bank of America, MoneyGram, eBay, TripAdvisor, and Vietnam Post, also had their websites spoofed by Triad Nexus, which also moved to prohibit access from U.S.-based IP addresses to circumvent sanctions.

"As the network continues to withdraw from direct U.S. exposure to avoid detection, it has been pivotally expanding into the Spanish, Vietnamese, and Indonesian markets. Using localized templates to target these regions, its goal is to ensure its illicit profits continue to flow," said Silent Push researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds