logo

Triad Nexus: Funnull malicious campaign (Campaign)

ID: 1a7a15b9-635d-5e1c-bf1a-17f0a6e3c64c

STIX ID: report--1a7a15b9-635d-5e1c-bf1a-17f0a6e3c64c

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2024-10-22

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Silent Push’s investigation reveals the FUNNULL CDN (Triad Nexus) is hosting a vast malicious infrastructure — over 200,000 generated domains — supporting gambling and investment scams, phishing, and money laundering, and was used in a supply-chain compromise via the polyfill.io library that affected more than 110,000 websites; the infrastructure shows links to laundering networks and alleged ties to North Korea’s Lazarus Group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.