Tracking the Triad Nexus: Investigating FUNNULL CDN's Role in Global Fraud and Money Laundering

Noah Plotkin (Solutions Engineer · Silent Push)

ShmooCon XX (Final) · Day 2 · Belay It

Overview

Noah Plotkin, a Solutions Engineer at Silent Push, delivered an insightful presentation at ShmooCon, shedding light on a sophisticated and pervasive cybercrime operation dubbed "Triad Nexus." This talk delves into the intricate web of deceit spun by FUNNULL CDN, a Chinese content delivery network that, despite its appearance as a legitimate service provider, has been uncovered as a central enabler of global fraud and money laundering. Plotkin's research, a collaborative effort with his colleagues at Silent Push, meticulously maps FUNNULL's infrastructure, revealing its deep involvement in hosting pig butchering scams, retail phishing campaigns, and illicit online gambling operations.

Watch on YouTube

Visual summary for Tracking the Triad Nexus: Investigating FUNNULL CDN's Role in Global Fraud and Money Laundering by Noah Plotkin
Visual summary for Tracking the Triad Nexus: Investigating FUNNULL CDN's Role in Global Fraud and Money Laundering by Noah Plotkin

Key moments

  1. 0:40 Introduction to Triad Nexus and Funnull CDN investigation
  2. 1:59 Uncovering Funnull's deeper involvement in criminal operations
  3. 4:00 Defining infrastructure laundering and its effectiveness
  4. 5:00 Polyfill.io supply chain attack and Funnull's acquisition
  5. 6:15 Identifying Funnull's parent: ACB Group and gambling ties

Tracking the Triad Nexus: Investigating FUNNULL CDN's Role in Global Fraud and Money Laundering

Speakers: Noah Plotkin, Solutions Engineer, Silent Push

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=5YHcw-qj094

Overview

Noah Plotkin, a Solutions Engineer at Silent Push, delivered an insightful presentation at ShmooCon, shedding light on a sophisticated and pervasive cybercrime operation dubbed "Triad Nexus." This talk delves into the intricate web of deceit spun by FUNNULL CDN, a Chinese content delivery network that, despite its appearance as a legitimate service provider, has been uncovered as a central enabler of global fraud and money laundering. Plotkin's research, a collaborative effort with his colleagues at Silent Push, meticulously maps FUNNULL's infrastructure, revealing its deep involvement in hosting pig butchering scams, retail phishing campaigns, and illicit online gambling operations.

The significance of this investigation extends beyond merely identifying a malicious CDN; it introduces and exemplifies the concept of infrastructure laundering. This technique, akin to financial money laundering, involves threat actors camouflaging their illicit activities by leveraging the credibility and vast networks of legitimate hosting providers, including major Western cloud services. FUNNULL CDN serves as a compelling case study for this practice, demonstrating how criminal enterprises can operate in plain sight, making detection and mitigation exceptionally challenging due to the inherent complexities of blocking shared infrastructure.

Plotkin's presentation not only details the technical mechanisms employed by FUNNULL to obscure its operations but also raises critical questions about the entity behind the network. The research probes whether FUNNULL is merely a compliant host or an active orchestrator of these criminal schemes, highlighting the broader industry challenge of tackling such complex, layered threats. The findings underscore the urgent need for enhanced collaboration among security researchers, law enforcement, and hosting providers to effectively dismantle these persistent and financially impactful networks.

Background

▶ Watch: Introduction to Triad Nexus and Funnull CDN investigation (0:40)

The investigation into FUNNULL CDN was primarily triggered by a significant event in February 2024: the polyfill.io supply chain attack. Polyfill.io was a legacy JavaScript product deeply embedded in hundreds of thousands of prominent websites, including government, enterprise, and popular streaming services like Hulu. FUNNULL acquired this domain, and within months, security firms detected that the access was being exploited. Mobile users visiting sites that relied on polyfill.io were being redirected to low-quality casino websites, turning a critical piece of web infrastructure into a vector for malicious activity. Namecheap ultimately intervened, taking down the domain and effectively ending the attack.

This incident immediately drew the attention of Silent Push researchers, who had previously encountered FUNNULL. Initially, the CDN was dismissed as merely having low security standards. However, the polyfill.io attack suggested a deeper, more active involvement in malicious operations. Further digging revealed that the parent owner of FUNNULL is the ACB Group, a Chinese entity with documented ties to various gambling organizations also based in China. This corporate structure immediately raised red flags, questioning the flow of money and the strategic acquisition of Western infrastructure by a group with such a profile.

Silent Push's historical data also proved crucial. Researchers revisited their archives from 2022, recalling a large-scale pig butchering campaign they had been tracking, a portion of which was hosted on FUNNULL. This historical context confirmed that FUNNULL's involvement in hosting investment scams and job scams was not a recent development but a persistent pattern spanning years. The re-examination of these older campaigns, coupled with the polyfill.io incident, cemented FUNNULL's status as a central player in a wide array of cybercriminal activities, prompting a comprehensive deep dive into its operational mechanics and its role in what Silent Push termed "infrastructure laundering."

Key Findings

▶ Watch: Uncovering Funnull's deeper involvement in criminal operations (1:59)

The investigation unveiled FUNNULL CDN as a sophisticated hub for global fraud and money laundering, deeply intertwined with various criminal enterprises. A critical finding was FUNNULL's long-standing role in hosting pig butchering campaigns since at least 2022. Researchers found that some of these fraudulent investment sites, such as one impersonating the CME Group (Chicago Mercantile Exchange), remained active in 2024, demonstrating remarkable persistence and a failure of conventional takedown efforts. This longevity allowed Silent Push to map changes in FUNNULL's infrastructure over time, providing invaluable insights into its operational resilience.

A cornerstone of FUNNULL's obfuscation strategy is its extensive use of Cname chains. These DNS records, typically used for legitimate redirection, are leveraged by FUNNULL to mask the true underlying infrastructure of its clients. The talk detailed how FUNNULL systematically changes the domains used for Cname mapping, evolving from funnel.vip to funnel01.vip, and later to fn3.vip. This non-standard behavior for a legitimate network signals a deliberate attempt to evade detection and tracking. By performing forward lookups on these Cnames, Silent Push could identify the vast pool of IP addresses hosting FUNNULL's content, revealing an unusual distribution across numerous Autonomous System Numbers (ASNs) globally, a stark contrast to the geographically localized ASNs typically used by legitimate web hosts.

The research also uncovered FUNNULL's practice of infrastructure laundering, where it rents IP space from major Western hosting providers and blends it with Chinese hosting infrastructure. This mixed environment provides an obfuscation layer, making it extremely challenging for defenders to block malicious activity without causing significant collateral damage to legitimate services. FUNNULL appears to operate a bulk hosting model, offering significant discounts to clients hosting 50 or more domains, a business strategy seemingly tailored to attract and facilitate mass-scale malicious operations. The presence of a consistent error message page, identifiable by its HTML body ssdh, also served as a valuable fingerprint for mapping FUNNULL's extensive infrastructure.

Further content analysis revealed tens of thousands of fraudulent casino websites hosted on FUNNULL, many impersonating well-known brands like Sun City Group and Bet365. Initial assumptions of complicity by these brands were challenged when BWI, a casino company, confirmed that a site uncovered by Silent Push was fraudulent. A deep dive into the source code of these fraudulent casino sites led to a crucial discovery: many referenced a public GitHub account. This repository contained shared templates and common code, strongly suggesting a single developer or team likely working directly for FUNNULL to build these web pages. Inside this repository, a page containing a specific Mandarin phrase commonly associated with money laundering operations was found, along with direct links to Telegram channels and email addresses. These Telegram channels explicitly advertised a "running points team," a term linked to money laundering, openly bragging about their money-moving network and inviting participants to join.

Finally, the investigation identified a significant cluster of infrastructure dedicated to retail phishing websites, targeting over 20 major retail and luxury brands. All these phishing pages and investment scams were hosted on a single, specific FUNNULL Cname, indicating that FUNNULL not only hosted but likely helped set up this infrastructure for its clients. These retail phishing scams were distributed across nine different ASNs, further illustrating FUNNULL's infrastructure laundering tactics and the jurisdictional complexities involved in takedown attempts.

Technical Deep Dive

▶ Watch: Defining infrastructure laundering and its effectiveness (4:00)

FUNNULL CDN's operational sophistication lies in its multi-layered approach to infrastructure obfuscation, primarily leveraging Cname chains and a distributed hosting model. As detailed by Plotkin, a Cname record acts as an alias, mapping one domain to another. FUNNULL exploits this by creating multi-stage Cname chains. For instance, a customer's malicious domain might resolve to fn3.vip, which then resolves to another Cname, and finally to a diverse pool of IP addresses. This chaining mechanism makes it difficult to directly trace a malicious domain back to its ultimate hosting infrastructure.

A key technical observation was the dynamic nature of these Cname domains. FUNNULL consistently changes the domains it uses for Cname mapping (e.g., from funnel.vip to funnel01.vip to fn3.vip). This behavior is highly unusual for legitimate CDNs, which typically maintain stable, branded Cname endpoints. This constant rotation serves to frustrate tracking efforts and requires continuous re-mapping by security researchers.

To uncover the underlying infrastructure, Silent Push employed a method involving forward DNS lookups on the Cname records. By resolving the Cname associated with a client's domain, researchers could obtain a list of IP addresses hosting the content. This analysis revealed a highly unusual pattern: FUNNULL's IPs were mapped to numerous, seemingly random Autonomous System Numbers (ASNs) across the globe. In contrast, legitimate web hosts and CDNs typically assign ASNs based on geographic proximity to the client's server, utilizing edge networks for localized content delivery. FUNNULL's global, fragmented ASN distribution is a hallmark of its infrastructure laundering strategy, enabling it to rent IP space from diverse providers, including major Western cloud services and Chinese hosting providers. This blending of legitimate and suspect infrastructure creates a significant challenge for network defenders, as blocking an entire IP range could inadvertently disrupt thousands of legitimate websites.

The bulk hosting model further exacerbates the problem. FUNNULL offers substantial discounts for clients hosting 50 or more domains, indicating a business model designed to attract large-scale malicious operations. This allows threat actors to rapidly deploy thousands of fraudulent sites, overwhelming traditional detection and takedown mechanisms. Silent Push found that a consistent error message page, identified by its HTML body ssdh, served as a reliable indicator for mapping FUNNULL-hosted IPs and understanding the ASNs involved. This specific fingerprint provided a crucial tool for scaling their investigative efforts.

The discovery of shared code and templates for the tens of thousands of fraudulent casino sites was another significant technical finding. Silent Push utilized a sophisticated querying technique within the Silent Push platform, combining analysis of reference JavaScript files, HTML content and titles, HTTP response software, ASNs, and favicon values to identify commonalities across these sites. This led to the identification of a public GitHub repository containing the templates used to construct the fraudulent gambling sites. The presence of a specific Mandarin phrase within this repository, commonly associated with money laundering, alongside direct links to Telegram channels and email addresses, provided undeniable evidence of a coordinated, organized criminal operation. The Telegram channels themselves served as advertisements for a "running points team," explicitly detailing how funds were moved through the fraudulent casino brands, aligning with well-documented money laundering schemes.

The analysis of retail phishing campaigns further solidified the understanding of FUNNULL's operations. The observation that an entire FUNNULL Cname was dedicated to hosting phishing pages targeting over 20 major brands, distributed across nine different ASNs, underscored the CDN's active role in facilitating these schemes. This dedicated infrastructure, combined with the mixed legitimate/suspect hosting, highlights FUNNULL's deliberate strategy to create a resilient and difficult-to-disrupt platform for a wide array of cybercriminal activities.

Demo / Proof of Concept

▶ Watch: Polyfill.io supply chain attack and Funnull's acquisition (5:00)

Noah Plotkin's presentation on FUNNULL CDN, while rich in detailed technical analysis and investigative findings, did not include a live demonstration or a proof of concept specific to the FUNNULL infrastructure. The talk focused on presenting the extensive research conducted by Silent Push and the evidence gathered through their tracking and analysis of FUNNULL's operations and its criminal clients.

Defensive Implications

▶ Watch: Identifying Funnull's parent: ACB Group and gambling ties (6:15)

The detailed investigation into FUNNULL CDN and the concept of infrastructure laundering presents significant challenges and crucial implications for cybersecurity defenders. The primary defensive hurdle lies in the blended nature of FUNNULL's hosting environment. Since FUNNULL rents IP space from legitimate, major Western hosting providers and mixes it with Chinese infrastructure, simply blocking an entire IP range associated with FUNNULL could lead to severe collateral damage, disrupting thousands of legitimate businesses unknowingly co-located with malicious activity. This makes traditional IP-based blocking strategies highly problematic and often unfeasible.

Defenders must shift their focus from reactive IP blocking to more proactive and intelligent detection methods. This includes:

  1. Enhanced DNS Monitoring and Cname Chain Analysis: Organizations should implement advanced DNS monitoring to detect anomalous Cname chain patterns, especially those that frequently change or resolve to unusual and geographically diverse ASNs. Identifying these obscure Cname structures can serve as an early warning indicator of infrastructure laundering.
  2. Reputation Scoring of Hosting Providers: A more granular approach to assessing the reputation of hosting providers is needed. While blocking major cloud providers is impractical, identifying specific subnets or ASN blocks within these providers that are consistently associated with FUNNULL or similar suspect CDNs can enable more targeted mitigation without broad collateral damage.
  3. Brand Impersonation and Phishing Detection: Given the prevalence of retail phishing and fraudulent casino sites, organizations must invest in robust brand monitoring solutions that can quickly detect and report impersonating domains. This includes not only direct domain matches but also visual similarity detection and analysis of site content (e.g., shared JavaScript files, HTML structures, favicons) that match known criminal templates.
  4. Collaboration and Information Sharing: The complex, cross-jurisdictional nature of FUNNULL's operations necessitates increased collaboration. Security researchers, law enforcement agencies, and legitimate hosting providers must share intelligence on malicious infrastructure, Cname patterns, and associated criminal groups. This collective effort is crucial for coordinating takedown attempts and overcoming jurisdictional barriers.
  5. Leveraging Unique Artifacts for Detection: The discovery of consistent error pages (e.g., HTML body ssdh) or specific code references (like the GitHub repository) provides unique fingerprints for identifying FUNNULL-hosted infrastructure. Defenders can integrate these artifacts into their detection rules and threat intelligence platforms to improve the accuracy of identifying malicious sites.
  6. Supply Chain Security Awareness: The polyfill.io attack highlights the critical importance of supply chain security. Organizations must meticulously vet third-party JavaScript libraries, CDNs, and other external dependencies, ensuring that the providers maintain high security standards and are not susceptible to acquisition by malicious entities. Regular audits and integrity checks of these dependencies are paramount.
  7. Addressing Money Laundering Infrastructure: The explicit links to Telegram channels coordinating "running points teams" underscore the need for financial institutions and cryptocurrency platforms (like Tether, which was implicated in some of the fraudulent casino sites) to enhance their anti-money laundering (AML) controls and collaborate with law enforcement to disrupt these financial networks.

Ultimately, combating threats like FUNNULL requires a multi-faceted approach that combines technical vigilance, intelligence sharing, and concerted efforts to address the legal and jurisdictional challenges posed by globally distributed criminal infrastructure.

Key Takeaways

  • FUNNULL CDN is a Major Cybercrime Enabler: The investigation confirmed FUNNULL CDN as a central hub for global fraud, actively hosting and potentially orchestrating pig butchering scams, retail phishing campaigns targeting major brands, and extensive online gambling and money laundering operations since at least 2022.
  • Infrastructure Laundering is a Sophisticated Evasion Tactic: FUNNULL exemplifies "infrastructure laundering" by blending IP space rented from legitimate Western hosting providers with Chinese infrastructure. This strategy allows criminal activities to hide in plain sight, making detection and mitigation difficult due to the risk of collateral damage to legitimate services.
  • Cname Chains and Bulk Hosting Drive Obfuscation and Scale: FUNNULL extensively uses dynamic Cname chains (e.g., funnel.vip to fn3.vip) to obscure its true infrastructure and operates a bulk hosting model, offering discounts for 50+ domains. These tactics enable rapid, large-scale deployment of malicious sites and complicate tracking efforts.
  • Evidence Suggests Direct Involvement: Discoveries like a dedicated Cname for retail phishing, shared code templates for thousands of fraudulent casino sites, a GitHub repository containing these templates, and explicit links to Telegram channels coordinating money laundering operations strongly suggest FUNNULL's direct involvement or deep complicity beyond mere hosting.
  • Takedown Efforts Face Significant Challenges: The distributed nature of FUNNULL's infrastructure across various ASNs globally, combined with the jurisdictional complexities of Chinese and Western hosting, makes effective takedown attempts exceptionally challenging and often prolonged.
  • Collaboration and Advanced Analytics are Crucial: Tackling complex threats like FUNNULL requires enhanced collaboration between security researchers, law enforcement, and hosting providers. Advanced analytical techniques for DNS monitoring, content fingerprinting, and infrastructure mapping are essential to identify and disrupt these persistent networks.

About the Speaker(s)

Noah Plotkin is a Solutions Engineer at Silent Push. He expressed his enthusiasm for discussing "Triad Nexus," one of the most intriguing and complex investigations undertaken by his team. Plotkin emphasized that while he presented the findings, the investigation was a collaborative effort, acknowledging the significant contributions of his colleagues at Silent Push. His expertise lies in uncovering and analyzing sophisticated cybercriminal infrastructures, particularly those employing advanced obfuscation techniques.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk delivers a deep, technically sound investigation into FUNNULL CDN's extensive role in global cybercrime. It meticulously details their

Heather Calloway (CISO) — STRONG ACCEPT

This presentation provides a critical, unvarnished look at how sophisticated criminal enterprises are leveraging legitimate infrastructure for global fraud and money laundering. The concept of "infrastructure laundering" is a powerful diagnostic for understanding a systemic problem that transcends traditional technical defenses, demanding a C-suite and board-level understanding of supply chain risk, financial exposure, and institutional accountability. While the ultimate solutions remain complex, the research offers clear, actionable insights for defenders and leaders grappling with these pervasive threats.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)