RingH23 Threat Actors Target MacCMS and CDN Infrastructure with New Arsenal
ID: b270f588-1b3b-5649-8d46-26489c629933
STIX ID: report--b270f588-1b3b-5649-8d46-26489c629933
Feed Name: GBHackers
Researchers report that the Funnull cybercrime group has deployed a Linux toolkit dubbed RingH23 to perform large-scale supply-chain and CDN compromises: poisoning MacCMS’s update channel and breaching GoEdge-based CDN nodes to install an LD_PRELOAD rootkit, Nginx injection modules, and backdoors that inject malicious JavaScript to redirect millions of users to gambling, pornography, and fraud sites; the report includes telemetry on infection scale, detailed IOCs (udev rules, libutilkeybd.so, /var/adm staging), and mitigation guidance to audit MacCMS installs and CDN edge nodes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
