Funnull Resurfaces: Exposing RingH23 Arsenal and MacCMS Supply Chain Attacks
ID: 1642b53c-099a-5246-ba08-888cab9340fc
STIX ID: report--1642b53c-099a-5246-ba08-888cab9340fc
Feed Name: QiAnXin XLab
This report details the re-emergence of the Funnull cybercriminal group and its upgraded RingH23 toolkit, which compromises CDN and CMS infrastructure to inject malicious JavaScript, hijack web traffic, and monetize users via gambling and adult sites; the campaign uses multi-stage Go binaries (infect_init, download_init), a backdoor (Badredis2s), an Nginx malicious module (Badnginx2s), an LD_PRELOAD rootkit (Badhide2s), and udev-based persistence, with widespread impact indicated by millions of potential affected users and extensive IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
