Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminal Group Funnull Unleashes RingH23 Attack Arsenal

Cybercriminal Group Funnull Unleashes RingH23 Attack Arsenal

Posted on March 5, 2026 By CWS

The notorious cybercriminal group Funnull has made headlines again with their latest exploit, the RingH23 toolkit, which is targeting CDN nodes and the MacCMS content management system. This new development has escalated their operations, redirecting unsuspecting users to illegal websites at an alarming scale.

Funnull’s Evolution and New Threats

Funnull, also known as Fangneng CDN, has a long history of involvement in Southeast Asia’s cybercrime scene. Although registered as a legitimate CDN provider in the Philippines, the group has been linked to major scams, including fraudulent investment schemes resulting in losses over $200 million. Despite being sanctioned by the U.S. Treasury in May 2025, Funnull has resurfaced with a more sophisticated approach.

XLab analysts first detected the group’s renewed activities in July 2025. Their Cyber Threat Insight and Analysis System (CTIA) identified a suspicious ELF binary from the domain download.zhw[.]sh, which had evaded detection on VirusTotal. The domain client.110[.]nz recorded an unprecedented 1.6 billion DNS resolutions, indicating a widespread operation rather than isolated incidents.

Infection Strategies and Techniques

Funnull employs two primary infection strategies. The first involves compromising GoEdge CDN management nodes to execute remote SSH commands, deploying the RingH23 toolkit. In the second method, they compromise the maccms.la update channel, inserting a malicious PHP backdoor that activates upon the administrator’s first login, evading forensic analysis by expiring the payload link shortly.

XLab’s telemetry data revealed over 10,748 infected IP addresses, mostly from streaming sites. One spoofed domain imitating Cloudflare amassed 340,000 unique visits in a single day, highlighting the massive reach of this operation. Researchers estimate that over one million users are daily subjected to malicious redirects due to this campaign.

Inside the RingH23 Toolkit

The RingH23 toolkit features a modular design, showcasing professional black-market development. The entry point, infect_init, is a Golang-based infector that executes after verifying credentials with a C2 server. It then spreads the download_init stage across connected servers, deploying various payloads including backdoors and rootkits.

The advanced Badredis2s backdoor uses encrypted WebSocket tunnels to maintain C2 communication, while the Badnginx2s module injects malicious JavaScript into outbound traffic. The Badhide2s rootkit conceals these activities, with defenders advised to set specific environment variables to reveal hidden components.

XLab advises discontinuing the use of maccms.la, auditing server files for malicious injections, and removing specific files to break infection cycles. Stay updated on this evolving threat through our channels on Google News, LinkedIn, and X.

Cyber Security News Tags:CDN, CDN infrastructure, cyber threat, Cyberattack, Cybercriminals, Cybersecurity, Funnull, MacCMS, MacCMS compromise, Malware, Phishing, RingH23, Scams, threat analysis, XLab

Post navigation

Previous Post: Threat Actors Exploit AI Tool to Spread Infostealer
Next Post: North Korean Hackers Target Crypto Firms in Sophisticated Attacks

Related Posts

Microsoft’s Critical Windows 11 Updates Enhance Security Microsoft’s Critical Windows 11 Updates Enhance Security Cyber Security News
Discord Implements Default E2EE for Voice and Video Discord Implements Default E2EE for Voice and Video Cyber Security News
Ransomware Threats Exploit Employee Monitoring Tools Ransomware Threats Exploit Employee Monitoring Tools Cyber Security News
Hackers Stolen Over 0 million by Exploiting Balancer DeFi protocol Hackers Stolen Over $100 million by Exploiting Balancer DeFi protocol Cyber Security News
MediaTek July 2025 Security Update Patches Vulnerabilities Affecting a Wide Range of Their Chipsets MediaTek July 2025 Security Update Patches Vulnerabilities Affecting a Wide Range of Their Chipsets Cyber Security News
Stolen API Key Causes ,000 Cloud Charges in Two Days Stolen API Key Causes $82,000 Cloud Charges in Two Days Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware
  • New Malware Exploits Microsoft 365 Calendars for Covert Commands
  • Critical WordPress RCE Vulnerability Discovered by AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware
  • New Malware Exploits Microsoft 365 Calendars for Covert Commands
  • Critical WordPress RCE Vulnerability Discovered by AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark