Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
5 malware families

Funnull

Also known asFunnullfunnull_technology_inc

Funnull, also referred to as Funnull Technology Inc., FUNNULL Technology Inc., and Fangneng CDN (方能CDN/方能科技), is described in the provided content as a Philippines-registered company and cybercriminal group that publicly claims to provide CDN services but has been linked to large-scale criminal infrastructure. The content states it has served as a core infrastructure provider for Southeast Asia’s cybercriminal ecosystem, particularly supporting romance baiting / “pig-butchering” and virtual-currency investment scams, gambling, money laundering, and related fraud operations. The U.S. Treasury Department’s Office of Foreign Assets Control sanctioned Funnull on May 29, 2025; the content also states Treasury sanctioned its administrator, Liu Lizhi, a Chinese national. Supporting reporting cited in the content links Funnull infrastructure to over 332,000 domains, and other reporting describes it as linked to over 1.4 million scam-hosting sites and to more than $200 million in U.S. victim losses. The content also links Funnull to supply-chain and traffic-redirection activity. It is described as having carried out a supply-chain attack on the Polyfill.io JavaScript library, and FUNNULL-operated infrastructure is referenced in malicious redirect chains observed in trojanized OphimCMS theme packages on Packagist. In that reporting, a FUNNULL-linked second-stage payload used heavily gated mobile-only redirection logic, anti-bot and anti-debugging checks, referrer requirements, time-of-day restrictions, second-visit cookies, and administrator-cookie exclusions before redirecting users to gambling or adult-content destinations. The domain union[.]macoms[.]la is specifically described as a documented Funnull IOC. The content further describes Funnull’s re-emergence with a server-side attack framework called RingH23. RingH23 is reported to compromise CDN infrastructure, including GoEdge management nodes and downstream edge nodes, and to poison the MacCMS (maccms.la) update channel to deploy malicious PHP backdoors. Reported components include an SSH-based propagation stage, a Golang infector, a downloader, an encrypted WebSocket backdoor that retrieves C2 information from Azure Blob Storage, DNS-tunneling fallback via iodine, a malicious Nginx module for JavaScript injection and cryptocurrency wallet-address swapping, and a userland rootkit using /etc/ld.so.preload for stealth. The campaign is described as enabling large-scale malicious JavaScript injection and redirection of users to gambling and pornographic sites, with many affected systems associated with streaming and movie-related websites. Based on the provided content, Funnull is a financially motivated cybercriminal actor and infrastructure provider, not described here as a state actor, although some commentary notes the broader difficulty of acting against cybercrime in jurisdictions where operators may have tacit government tolerance. No direct state attribution for Funnull is established in the provided material.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • crypto
  • finance
MITRE ATT&CK

Tradecraft

13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics25 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1195
Supply Chain Compromise
T1195.002
Compromise Software Supply Chain
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.007
JavaScript
TA0003
Persistence
2 techniques
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
T1547.010
Port Monitors
TA0004
Privilege Escalation
2 techniques
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
T1547.010
Port Monitors
TA0005
Stealth
3 techniques
T1014
Rootkit
T1027
Obfuscated Files or Information
T1027.002
Software Packing
T1078
Valid Accounts
TA0006
Credential Access
1 technique
T1557
Adversary-in-the-Middle
TA0007
Discovery
1 technique
T1654
Log Enumeration
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.004×2
SSH
TA0009
Collection
1 technique
T1557
Adversary-in-the-Middle
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1071.004
DNS
T1568
Dynamic Resolution
T1568.002
Domain Generation Algorithms
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

socket blogNews
Mar 12, 2026
6 Malicious Packagist Themes Ship Trojanized jQuery and FUNN...

Malicious infrastructure provider/CDN whose infrastructure is used as second-stage payload hosting and redirect infrastructure in a software supply-chain campaign (trojanized JS in PHP Composer themes). The FUNNULL-linked chain performs mobile-only, time-gated, anti-analysis checks and redirects victims to gambling/adult content; infrastructure remains actively maintained post-OFAC sanctions.

Read more
cyber security newsNews
Mar 5, 2026
Threat Actors Use New RingH23 Arsenal to Compromise MacCMS and CDN Infrastructure at Scale

Cybercriminal infrastructure/operator enabling and conducting large-scale malicious CDN and CMS supply-chain style compromises. Reported activity includes compromising GoEdge CDN management nodes to push payloads via SSH to edge nodes, poisoning the maccms.la update channel to deliver a PHP backdoor, and using the RingH23 framework to inject malicious JavaScript redirects, perform crypto wallet address replacement, and maintain stealth/persistence via a userland rootkit and DNS-tunneling fallback C2.

Read more
qianxin xlab blogNews
Mar 2, 2026
Funnull Resurfaces: Exposing RingH23 Arsenal and MacCMS Supply Chain Attacks

Cybercriminal infrastructure provider and active operator behind large-scale supply-chain and CDN/CMS poisoning used to hijack web traffic (malicious JavaScript injection/redirects), support pig-butchering scam ecosystems, and run a Linux server-side compromise framework (RingH23) that implants a modular backdoor/rootkit/Nginx module stack on CDN edge nodes for persistent control and monetization (gambling/porn redirects, wallet replacement, download hijacking).

Read more
krebs on securityNews
Dec 29, 2025
Happy 16th Birthday, KrebsOnSecurity.com!

Operated a content delivery network supporting China-based gambling, money laundering, and large-scale investment/romance scams ('pig butchering').

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping13

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.