logo

Funnull Resurfaces: Exposing RingH23 Arsenal and MacCMS Supply Chain Attacks

ID: 1642b53c-099a-5246-ba08-888cab9340fc

STIX ID: report--1642b53c-099a-5246-ba08-888cab9340fc

Feed Name: QiAnXin XLab

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-05-25

Author: Alex.Turing

...
...

This report details the re-emergence of the Funnull cybercriminal group and its upgraded RingH23 toolkit, which compromises CDN and CMS infrastructure to inject malicious JavaScript, hijack web traffic, and monetize users via gambling and adult sites; the campaign uses multi-stage Go binaries (infect_init, download_init), a backdoor (Badredis2s), an Nginx malicious module (Badnginx2s), an LD_PRELOAD rootkit (Badhide2s), and udev-based persistence, with widespread impact indicated by millions of potential affected users and extensive IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.