Funnull, also known as Funnull Technology Inc. and Fangneng CDN, is a Philippines-registered cybercriminal infrastructure provider sanctioned by the U.S. Treasury Department’s Office of Foreign Assets Control in May 2025. It has been associated with infrastructure supporting large-scale virtual-currency investment and romance-baiting scams, Chinese-language gambling and money-laundering operations, and fraudulent hosting at substantial scale. Its sanctioned administrator, Liu Lizhi, is a Chinese national. Funnull has been linked to supply-chain and traffic-hijacking activity, including abuse of CDN infrastructure and poisoning of software update channels to inject malicious client-side code. Reported operations associated with its RingH23 framework compromised CDN management infrastructure, propagated to edge nodes over SSH, deployed persistent Linux payloads, concealed artifacts through userland rootkit functionality, and used malicious web-server modules to inject JavaScript, redirect visitors to gambling and adult sites, and substitute cryptocurrency wallet addresses. The framework also used encrypted web-based command-and-control with DNS-tunneling fallback. Funnull-linked infrastructure has additionally been used by distinct third-party operators conducting malicious package campaigns against Vietnamese streaming sites; those tenant operations should not be conflated with Funnull itself. Funnull’s primary role is the provision and operation of criminal infrastructure, although evidence also links it to direct supply-chain compromise and web-traffic manipulation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
66 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a large active network of Chinese-language casino domains, supported by bulletproof CDN infrastructure, that facilitates illegal gambling and money laundering.
Referenced only as a weak code-structure comparison involving custom nginx HTTP filters and XOR-encrypted configuration; no meaningful operational linkage is established.
Linked infrastructure provider/entity previously sanctioned by the United States for facilitating scams; the reporting does not establish that Funnull operated the malicious Composer-package and iOS-spyware campaign.
Infrastructure et acteur cybercriminel associé à une campagne de compromission de dépendances Composer ciblant des sites vietnamiens de streaming. La campagne injecte du JavaScript malveillant, réalise des redirections vers des jeux d’argent et distribue une chaîne iOS WebKit-vers-kernel qui déploie un spyware de collecte de données et de portefeuilles crypto.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.