logo

Threat Actors Use New RingH23 Arsenal to Compromise MacCMS and CDN Infrastructure at Scale

ID: 1c2f49db-981a-5ae5-8e14-f105ad3bf2b8

STIX ID: report--1c2f49db-981a-5ae5-8e14-f105ad3bf2b8

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-03-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

XLab reports that the Funnull criminal group (previously OFAC-sanctioned) resurfaced with a sophisticated server-side toolkit named RingH23, compromising CDN management and poisoning the maccms.la update channel to deploy backdoors, an Nginx module, and a rootkit; telemetry shows at least 10,748 infected IPs and an estimated exposure of over one million users per day, with detailed TTPs, IoCs, and remediation advice provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.