围剿FUNNULL黑产:深度揭秘RingH23与MacCMS投毒攻击链
ID: 40da1d92-6969-5347-863b-0d3d387c855f
STIX ID: report--40da1d92-6969-5347-863b-0d3d387c855f
Feed Name: QiAnXin XLab
**Executive summary:** This report documents the resurgence of the Funnull criminal infrastructure and a sophisticated campaign (RingH23) that compromises GoEdge CDN management nodes and the maccms.la upgrade channel to deploy a modular Linux attack suite (Badnginx2s, Badredis2s, Badhide2s) capable of web JS supply‑chain poisoning, user redirection to fraud/porn/gambling sites, wallet address hijacking, persistent udev/LD_PRELOAD rootkit mechanisms, and multi-channel C2 (Azure Blob, WSS, DNS tunnel); the activity has widespread impact with tens of thousands of infected IPs and estimated daily user exposure in the hundreds of thousands to millions, and the report includes actionable IOCs and cleanup guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
