Triad Nexus: Funnull malicious campaign (Campaign)
ID: 1a7a15b9-635d-5e1c-bf1a-17f0a6e3c64c
STIX ID: report--1a7a15b9-635d-5e1c-bf1a-17f0a6e3c64c
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-22
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Silent Push’s investigation reveals the FUNNULL CDN (Triad Nexus) is hosting a vast malicious infrastructure — over 200,000 generated domains — supporting gambling and investment scams, phishing, and money laundering, and was used in a supply-chain compromise via the polyfill.io library that affected more than 110,000 websites; the infrastructure shows links to laundering networks and alleged ties to North Korea’s Lazarus Group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
