Triad Nexus is an illicit cybercrime network associated with large-scale online fraud, particularly pig-butchering cryptocurrency investment scams, fraudulent trading platforms, suspicious gambling services, and related money-laundering activity. The network has been tied to the Funnull content delivery and hosting ecosystem and is described as deeply rooted in organized criminal networks across Asia. It has been linked to extensive victim losses and to a very large fraud infrastructure spanning more than 200,000 unique hostnames. Triad Nexus operates scam portals that impersonate trusted brands and services across financial, banking, luxury retail, money transfer, travel, and postal themes. Reported impersonation targets have included major banks, remittance providers, consumer platforms, and luxury brands. The group uses localized templates to tailor fraudulent portals to specific regional audiences and has expanded activity toward Spanish-, Vietnamese-, and Indonesian-language markets while deliberately reducing direct exposure to the United States. A defining feature of Triad Nexus is its sophisticated infrastructure laundering and operational security. After sanctions pressure on Funnull, the group rebuilt its infrastructure using front companies with fabricated corporate histories and professional branding, geographic fencing to block or limit access from selected regions, and multi-layered DNS redirection designed to obscure final hosting destinations. It has used large pools of rotating CNAME infrastructure and routed traffic through reputable cloud providers to make scam portals appear legitimate and harder to trace or block. The group has also hijacked or illicitly obtained enterprise cloud accounts across major providers to support these operations. Triad Nexus demonstrates strong defense-evasion tradecraft through geofencing, rotating infrastructure, layered redirection, and abuse of trusted cloud services. Its activity centers on fraud and illicit profit generation rather than espionage or destructive operations. No distinct sub-groups are directly supported by the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Improving operational security by using geographic fencing and laundering infrastructure through front companies.
Cybercrime network conducting infrastructure laundering, geofencing, and use of front companies to expand fraudulent scam activity into emerging markets while reducing U.S. exposure. It also exploits major cloud services to obtain accounts that lend legitimacy to scams and spoofs well-known organizations' websites.
Operates a large-scale global fraud network tied to the FUNNULL CDN, primarily conducting pig butchering scams, investment fraud, money laundering, illegal gambling, and brand-impersonation scam portals. After U.S. sanctions, it shifted to more evasive infrastructure by laundering traffic through hijacked enterprise cloud accounts and rotating multi-layered CNAME chains.
投資詐欺(いわゆるpig butchering/ロマンス詐欺)や偽トレーディングアプリ、ギャンブル関連の不正サイト群を支える大規模インフラ・ネットワーク。多数のホスト名を用い、詐欺プラットフォームのホスティング/運用を可能にするエコシステムとして言及されている。
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.