Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminal Group Funnull Unleashes RingH23 Attack Arsenal

Cybercriminal Group Funnull Unleashes RingH23 Attack Arsenal

Posted on March 5, 2026 By CWS

The notorious cybercriminal group Funnull has made headlines again with their latest exploit, the RingH23 toolkit, which is targeting CDN nodes and the MacCMS content management system. This new development has escalated their operations, redirecting unsuspecting users to illegal websites at an alarming scale.

Funnull’s Evolution and New Threats

Funnull, also known as Fangneng CDN, has a long history of involvement in Southeast Asia’s cybercrime scene. Although registered as a legitimate CDN provider in the Philippines, the group has been linked to major scams, including fraudulent investment schemes resulting in losses over $200 million. Despite being sanctioned by the U.S. Treasury in May 2025, Funnull has resurfaced with a more sophisticated approach.

XLab analysts first detected the group’s renewed activities in July 2025. Their Cyber Threat Insight and Analysis System (CTIA) identified a suspicious ELF binary from the domain download.zhw[.]sh, which had evaded detection on VirusTotal. The domain client.110[.]nz recorded an unprecedented 1.6 billion DNS resolutions, indicating a widespread operation rather than isolated incidents.

Infection Strategies and Techniques

Funnull employs two primary infection strategies. The first involves compromising GoEdge CDN management nodes to execute remote SSH commands, deploying the RingH23 toolkit. In the second method, they compromise the maccms.la update channel, inserting a malicious PHP backdoor that activates upon the administrator’s first login, evading forensic analysis by expiring the payload link shortly.

XLab’s telemetry data revealed over 10,748 infected IP addresses, mostly from streaming sites. One spoofed domain imitating Cloudflare amassed 340,000 unique visits in a single day, highlighting the massive reach of this operation. Researchers estimate that over one million users are daily subjected to malicious redirects due to this campaign.

Inside the RingH23 Toolkit

The RingH23 toolkit features a modular design, showcasing professional black-market development. The entry point, infect_init, is a Golang-based infector that executes after verifying credentials with a C2 server. It then spreads the download_init stage across connected servers, deploying various payloads including backdoors and rootkits.

The advanced Badredis2s backdoor uses encrypted WebSocket tunnels to maintain C2 communication, while the Badnginx2s module injects malicious JavaScript into outbound traffic. The Badhide2s rootkit conceals these activities, with defenders advised to set specific environment variables to reveal hidden components.

XLab advises discontinuing the use of maccms.la, auditing server files for malicious injections, and removing specific files to break infection cycles. Stay updated on this evolving threat through our channels on Google News, LinkedIn, and X.

Cyber Security News Tags:CDN, CDN infrastructure, cyber threat, Cyberattack, Cybercriminals, Cybersecurity, Funnull, MacCMS, MacCMS compromise, Malware, Phishing, RingH23, Scams, threat analysis, XLab

Post navigation

Previous Post: Threat Actors Exploit AI Tool to Spread Infostealer
Next Post: North Korean Hackers Target Crypto Firms in Sophisticated Attacks

Related Posts

DragonForce Ransomware Claimed To Compromise Over 120 Victims in The Past Year DragonForce Ransomware Claimed To Compromise Over 120 Victims in The Past Year Cyber Security News
FBI Warns of Fake Internet Crime Complaint Center (IC3) Website Used for Phishing Attacks FBI Warns of Fake Internet Crime Complaint Center (IC3) Website Used for Phishing Attacks Cyber Security News
Cyber Group Claims Massive Data Breach at Odido Cyber Group Claims Massive Data Breach at Odido Cyber Security News
Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack Cyber Security News
Predator Spyware Compamy Used 15 Zero-Days Since 2021 to Target iOS Users Predator Spyware Compamy Used 15 Zero-Days Since 2021 to Target iOS Users Cyber Security News
Don’t Click ‘Unsubscribe’ Links Blindly It May Leads to Loss of Credentials Don’t Click ‘Unsubscribe’ Links Blindly It May Leads to Loss of Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic’s New AI Model Faces Early Security Breach
  • IronWorm Threat Exploits npm to Steal Developer Data
  • CISA Alerts on Magento Cache Warmer Security Vulnerability
  • Agentic AI’s Role in Defense Hinges on Secure Infrastructure
  • Stock Exchange Exec’s Email Breach: Insights Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic’s New AI Model Faces Early Security Breach
  • IronWorm Threat Exploits npm to Steal Developer Data
  • CISA Alerts on Magento Cache Warmer Security Vulnerability
  • Agentic AI’s Role in Defense Hinges on Secure Infrastructure
  • Stock Exchange Exec’s Email Breach: Insights Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark