A Deep Dive into the Triad Nexus Pig Butchering & Money Laundering Operation

Zach Edwards

BSidesSF 2025 — Here Be Dragons · Day 2 · Main

Overview

Zach Edwards, senior threat analyst at Silent Push, exposed Triad Nexus — a Chinese-operated CDN called Funnel that serves as critical infrastructure for large-scale investment scams, money laundering operations, and retail phishing campaigns. The network stays online by illicitly acquiring IP addresses from cloud providers including Amazon AWS, a technique Edwards calls "infrastructure laundering." Despite public disclosure in December 2024 and a follow-up report in February 2025, the network was still fully operational at the time of his BSidesSF talk. ---

Watch on YouTube

Visual summary for A Deep Dive into the Triad Nexus Pig Butchering & Money Laundering Operation by Zach Edwards
Visual summary for A Deep Dive into the Triad Nexus Pig Butchering & Money Laundering Operation by Zach Edwards

Key moments

  1. 2:41 Attribution: ACB Group—massive gambling ring—is corporate entity behind Funnel CDN
  2. 2:54 Infrastructure laundering: new bulletproof hosting via stolen cloud provider accounts
  3. 4:40 Amazon abuse: attackers create fake AWS accounts, IPs rotated every 24-72 hours
  4. 6:04 Polyfill.io supply chain: Chinese entity redirected millions of sites to scam casinos
  5. 6:35 Key discovery: Funnel (polyfill parent) is core infrastructure for pig butchering scams
  6. 7:43 Ongoing threat: network still active today with continuously refreshed cloud IPs
  7. 9:26 Investment scam scope: fake Coinbase/NASDAQ/eToro sites hosted on laundered AWS IPs
  8. 10:33 CNAME tracking technique: oldest domain CNAME records reveal full infrastructure map

A Deep Dive into the Triad Nexus Pig Butchering & Money Laundering Operation

Speaker: Zach Edwards

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: https://www.youtube.com/watch?v=-rY3MfKRfWo

Reading time: ~8 minutes

TL;DR

Zach Edwards, senior threat analyst at Silent Push, exposed Triad Nexus — a Chinese-operated CDN called Funnel that serves as critical infrastructure for large-scale investment scams, money laundering operations, and retail phishing campaigns. The network stays online by illicitly acquiring IP addresses from cloud providers including Amazon AWS, a technique Edwards calls "infrastructure laundering." Despite public disclosure in December 2024 and a follow-up report in February 2025, the network was still fully operational at the time of his BSidesSF talk.

Introduction

The term "pig butchering" — a phrase the threat actors themselves coined to describe systematically draining victims of all their money — has become shorthand for a billion-dollar criminal industry. But the infrastructure enabling these scams has remained poorly understood, often dismissed as a murky tangle of low-quality overseas hosting. At BSidesSF 2025, Zach Edwards pulled back the curtain on one specific node in this ecosystem: a CDN operator called Funnel, a subsidiary of the Chinese online gambling conglomerate ACB Group, which is providing bulletproof-style hosting to investment scammers, money launderers, and phishing operators — while quietly abusing the IP ranges of major cloud providers to stay online.

What makes this research particularly striking is its origin. Funnel entered public consciousness in 2024 not through a security disclosure, but through a JavaScript supply chain attack — the compromise of the widely embedded polyfill.io domain — that redirected millions of users to sketchy casino websites. Most analysts filed it away as a low-sophistication annoyance. Edwards and his team at Silent Push kept digging and found something far more serious underneath.

From Polyfill to Pig Butchering: How Funnel Came to Light

▶ Watch: The Polyfill Connection (02:15)

In February 2024, the polyfill.io domain — a JavaScript utility embedded in the pages of organizations ranging from nasa.gov to Hulu — was sold to a Chinese entity. By July 2024, security researchers noticed that the new owners were using the domain to redirect mobile visitors to low-quality online casino websites. Google pulled ads from any site running the snippet, and Namecheap eventually banned the domain. The incident looked like a strange, poorly monetized supply chain attack, and much of the security community moved on.

Silent Push recognized the brand behind the acquisition: Funnel. The team had encountered Funnel previously in investment scam research but hadn't investigated it deeply. The polyfill incident changed that calculus entirely. "Oh my goodness, Funnel itself may be the malicious entity," Edwards recalled thinking. Funnel, it turned out, is a subsidiary of ACB Group, a sprawling online gambling organization with extensive relationships across Europe and Asia, and its own bragging points about owning infrastructure inside China.

Funnel markets itself as a CDN offering bulk domain registration, with pricing structures clearly oriented toward clients managing thousands of domains at a time. Its DNS architecture, however, diverges sharply from any legitimate enterprise use: the network cycles through a chain of CNAME records — rotating from afunnel.vip to funnel01.vip to fn3.vip — in a way that would force every legitimate client to update their own DNS configurations repeatedly. No normal CDN operates this way. The reason becomes apparent when you look at where those CNAME chains ultimately resolve.

Infrastructure Laundering: A New Form of Bulletproof Hosting

▶ Watch: How Infrastructure Laundering Works (08:40)

Edwards introduced a concept he calls "infrastructure laundering" — a technique that functions like bulletproof hosting but is significantly harder to defend against. A classic bulletproof host operates on a fixed set of IP ranges; defenders can block the entire ASN. Funnel's approach is different: it maps its CNAME chains to a rotating pool of IP addresses, some on low-quality Asian hosts, others on the IP ranges of major cloud providers — including Amazon AWS — acquired through fake accounts, stolen credentials, and stolen credit cards.

When an Amazon IP maps into Funnel's CNAME chain, it typically stays live for 24 to 72 hours before Amazon security detects and removes it. Funnel simply moves to the next illicitly acquired IP. The cycle has repeated continuously. "Amazon released a giant statement sort of saying, 'We've got this under control. This is old news. This isn't happening anymore,'" Edwards noted. "Well, sorry folks, it's still happening today." Microsoft was targeted early in Funnel's lifecycle but appears to have developed effective countermeasures. Edwards urged other cloud providers to share Microsoft's apparent best practices, and warned that "this time next year, there's probably going to be even more similar networks just like this."

The defensive challenge is acute: blocking a bulletproof host's fixed ASN range is straightforward. Blocking domains that constantly spin up is manageable with threat intelligence. But blocking a threat that continuously rotates onto fresh IP addresses within Amazon's own cloud ranges — without blocking legitimate Amazon traffic — is a fundamentally different problem. Edwards believes Funnel specifically pursues Western cloud IPs because its victims are predominantly Western, and the credibility and load speed of a US-based IP makes the scam pages more convincing.

For defenders investigating the network, Edwards offered a practical fingerprint: Funnel serves consistent error pages that include the word "funnel" — any IP resolving that error code is mapped into Funnel's infrastructure.

The Casino Laundering Network

▶ Watch: Fake Casinos and Money Laundering (18:50)

Alongside the investment scam sites, Silent Push found a large cluster of casino websites on Funnel's infrastructure — pages impersonating major global casino brands including BWIN, all built from the same template. The sites advertised identical bonuses and Tether lotteries, and carried identical language across dozens of domains. By fingerprinting the sites via their favicons, the team could track all impersonated brands using fewer than a dozen favicon queries.

When TechCrunch helped reach out to BWIN for comment, the company confirmed it had no connection to the sites and was actively trying to get them removed. The fake casino network is not a gambling operation — it is a money laundering vehicle. Edwards found references to "Sun City Group" embedded in the sites' code. Sun City Group is one of the most significant casino money laundering operations ever documented; its CEO is currently facing an 18-year sentence for laundering an estimated $100 billion, including $20 million on behalf of North Korea's Lazarus Group. Both of the United Nations Office on Drugs and Crime's recent reports on the topic include screenshots visually identical to the fake casino sites on Funnel's infrastructure.

The laundering mechanism, confirmed through Telegram accounts embedded in the sites' GitHub repositories, works as follows: a user deposits Tether cryptocurrency into one of the fake casino accounts; they then visit a physical junket location or affiliated business; the operator takes a 10% cut and provides cash or local currency in return. The Telegram conversations were explicit about the mechanics, and even offered prospective clients their choice of casino brand to launder funds through.

Retail Phishing, DGA Domains, and the Scale of the Problem

▶ Watch: Retail Phishing and Infrastructure Scale (26:10)

Beyond investment fraud and money laundering, Funnel hosts a large retail phishing operation spanning dozens of well-known consumer brands. Notably, all of the phishing sites share a single CNAME — indicating that Funnel segments its clients by CNAME, and that investigators can potentially track individual threat actors by which CNAME chain their infrastructure sits on.

The domain portfolio across the network skews heavily toward DGA-style Chinese numeric domains. Edwards believes this serves two purposes: circumventing the Great Firewall for operational management, and making it difficult for abuse complaints to find a stable target. CTG Server is Funnel's single largest IP source and, notably, the top IP source for many other investment scheme networks — making it a productive starting point for anyone investigating this class of threat.

Edwards closed with a broader warning: Funnel is "one small piece" of a larger ecosystem. Silent Push is tracking a parallel infrastructure with over 1,500 CNAME records, dynamically spinning up new entries. The pattern Funnel pioneered is already being replicated. "Bulletproof hosting has a new family member," he said, "and it's called infrastructure laundering."

Notable Quotes

"If you're facing a threat that is constantly spinning up domains and hosting them on IPs that are on giant Amazon cloud ranges, you either have to know those domains and block them in real time or somehow navigate some partial blocking on an IP range — which, good luck with that."

— Zach Edwards, ▶ 22:30

"We know exactly how they're mapping this. In theory, as soon as any IP address hits one of their CNAMEs, you should have some sort of remediation process to get that taken down as fast as possible. But if you don't, they're going to keep attacking you."

— Zach Edwards, ▶ 24:10

"Pig butchering is just the concept of taking all the money someone has. The threat actors came up with that term — from snout to tail, they want to take all of your money. They really are quite good at ramping up how much money they take from you, where it may start with a hundred bucks and by the end of it you've given them $25,000."

— Zach Edwards, ▶ 38:45

Key Takeaways

  • Infrastructure laundering is the new bulletproof hosting. By routing CNAME chains through illicitly acquired cloud provider IPs that rotate every 24–72 hours, Funnel evades the traditional countermeasure of blocking fixed ASN ranges. Classic blocklist defenses do not work against this model.
  • Funnel is a subsidiary of ACB Group, a major Chinese online gambling conglomerate also linked to the 2024 polyfill.io supply chain attack. The same entity is hosting investment scams, a Tether-based money laundering network tied to Sun City Group, and retail phishing operations.
  • Fake casino sites are money laundering infrastructure, not gambling operations. The Telegram-confirmed scheme allows users to deposit cryptocurrency and withdraw cash at physical junket locations, with operators taking a 10% cut.
  • CTG Server is the network's primary IP supplier and a common denominator across multiple investment scheme infrastructures — a useful pivot point for threat investigators.
  • CNAME segmentation is a fingerprinting opportunity. Funnel appears to segment clients by CNAME chain; analysts can track individual threat actor clusters by identifying which chain their domains sit on.
  • Knowledge sharing is essential to defense. This research would not have been possible without prior public reporting on polyfill and investment scam infrastructure. Defenders with relevant leads — especially those with access to NetFlow data — are urged to share findings with law enforcement and the research community.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Edwards traced a CDN called Funnel from the polyfill.io supply chain attack through investment scams, a Tether money laundering network with documented Sun City Group ties, retail phishing, and a technique he calls infrastructure laundering — rotating through illicitly acquired AWS IP ranges every 24-72 hours. Still fully operational at the time of the talk. This is serious threat intelligence research, not a blog post.

Heather Calloway (CISO) — STRONG ACCEPT

Edwards traced a Chinese-operated CDN providing infrastructure to investment scammers and money launderers — actively using illicitly acquired AWS IP ranges to stay online — from the polyfill.io incident through a still-operational bulletproof hosting network. Infrastructure laundering is a harder problem than traditional bulletproof hosting, and most defenders haven't thought about how to address it.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons