Event Overview
Triad Nexusis a fraudulent infrastructure network linked to the Asian organized crime ecosystem, focusing on cryptocurrency investment scams and high-fidelity brand impersonation. Historically, it has been closely tied toFUNNULL CDN. In May 2025, the U.S. Treasury Department designated FUNNULL as an infrastructure provider supporting "hundreds of thousands" of virtual currency investment scam websites, noting its direct link to cases where U.S. victims reported losses exceeding $200 million. During the same period, the FBI released a FLASH report sharing CNAME and domain Indicators of Compromise (IOCs) with the private sector.
By April 2026,Silent Pushdisclosed that the network had completed a "de-FUNNULL-ization" and infrastructure laundering process following the sanctions. This involved rebranding front-end operations, using "clean" shell companies, implementing geofencing against the United States, and expanding operations into Vietnam, Indonesia, and Spanish-speaking markets.
For non-technical readers, the core of this incident is not a specific "virus," but rather anindustrialized fraud platform. It operates like a SaaS (Software as a Service) to mass-generate domains, rotate cloud IPs, and reuse counterfeit page templates to lead victims to fraudulent investment, payment, or KYC pages. Essentially, it is a "fraud supply chain" rather than a collection of isolated fake websites.
Timeline
The following timeline highlights reconstruction events disclosed within the last 30 days while tracing the network's evolution:
Key evidence in the timeline includes the Department of the Treasury's sanction announcement dated May 29,2025, the FBI's FLASH report issued on the same day, and Silent Push's technical disclosure dated April 14,2026, regarding "post-sanction persistence." The Department of the Treasury explicitly stated that FUNNULL supported "hundreds of thousands" of affected websites; the FBI quantified its infrastructure in the technical notice as comprising 548 CNAME records and over 332,000 function variable names.
Attack Chain Decomposition
It is important to clarify the concept of"Lateral Movement"in this context. In traditional enterprise intrusions, lateral movement refers to an attacker moving from one host to another within an internal network. In the case of Triad Nexus/FUNNULL, public evidence suggests the focus isInfrastructure Lateral Movement. This involves rapidly replicating the same templates, CNAME root domains, cloud IPs, and payment scripts across different brands, countries, and Top-Level Domains (TLDs).
Key Technologies and Operational Points
l Weaponizing Reusable Infrastructure: Rather than complex vulnerabilities, the core is the mass procurement of IPs from legitimate cloud providers, which are then resold to fraud groups. They use Domain Generation Algorithms (DGA) to create numerous similar domains and provide templates for impersonating trusted brands.
l Infrastructure Laundering: Post-sanction, the network hides fraudulent sites behind reputable cloud providers and Content Delivery Networks (CDNs) using shell companies and multi-layered CNAMEs. They utilize the infrastructure and reputation of ecosystems likeAmazon, Cloudflare, Google, and Microsoft, whileAS152194 (CTG Server Limited)remains a backbone.
l CNAME Chains and Domain Rotation: The network has evolved from nine stable CNAMEs to over175 randomly generated CNAMEs. FBI reports identified over332,000 unique domainsassociated with 548 unique CNAMEs.
l Templatized Brand Impersonation: Assets cover banking, fintech, luxury retail, logistics, and public services. These templates are paired with "Pig Butchering" tactics involving fabricated relationships and fake profit curves.
l Anti-Reconnaissance: The network uses geofencing to return"451 Unavailable for Legal Reasons"to U.S. visitors to evade law enforcement. They disguise themselves as legitimate CDN services (e.g., cdnbl[.]com, Yunray[.]ai) and communicate via Telegram (t[.]me/sara5433).
l Asset Liquidation: The network supports multiple cryptocurrencies (BTC, ETH, USDC, etc.) and typically moves stolen assets within48 hoursto compress the window for freezing funds.
Evidence and Key IOCs
The table below lists only representative IOC/retrievable features disclosed publicly and does not constitute a complete list. The full list of CNAME/functional variable names is significantly longer; FBI FLASH explicitly states that the publicly disclosed IOC represents only a portion.
Category | Public Example | Purpose / Description |
CNAME Root Domains
| funnullcdn.com、funnull01.vip、funnullv23.com、fn01.vip、fn02.vip、fn03.vip、funnull301.com、funnull6.com、funnull.org | FUNNULL/Triad Nexus The key root domain for generating and parsing function variable names; used by the FBI for analyzing the association between function variable names and CNAME records. |
Example of a counterfeit function variable name | coinbasepromxs.com、coinbase-shortterm.com、blackrockdejr.com、bakkt-crypto.com、aave-prooben.com、asx-royce.com | It reflects its strategies for addressing spelling variations and brand counterfeiting targeting encryption, asset management, and financial brands. |
Historical/Current Transfer CNAME | funnull[.]org、funnull[.]vip、funnull6[.]com、funnull301[.]com、fn01[.]vip、fn02[.]vip、fn03[.]vip、fc686[.]xyz、dns888[.]xyz、kanejwo[.]com、attackcdn[.]com、cdn899[.]com | It is used to associate the names of client functionality variables with the "whitened" cloud IP; cdn899[.]com is also utilized for fake casino or money laundering websites. |
CNAME link example | tripdsdvjea[.]com -> kanejwo[.]com -> iiauuw[.]com -> final A | A typical multi-level link demonstrates that simply examining the names of individual function variables is insufficient to reconstruct the backend infrastructure. |
Front-end/shell company example | cdnbl[.]com、CDN1[.]ai、Yunray[.]ai、CDN5[.]com、CTGCDN | The external brand shell, stripped of its "FUNNULL" elements following sanctions, is used to attract or disguise legitimate business operations. |
Manually operated contact point | t[.]me/sara5433 | The front-end operations/communication contact point indicates that it is not fully automated but involves human intervention. |
Infrastructure backbone | AS152194 (CTG Server Limited) | Silent Push considers it to remain a backbone load-bearing element; this is related to the segmentation of multiple ASN pools. |
The abused cloud ecosystem | AS16509、AS13335、AS396982、AS8075 | These solutions correspond to the cloud ecosystems of Amazon, Cloudflare, Google, and Microsoft, respectively, and are designed to enhance the level of "appearing trustworthy."These solutions correspond to the cloud ecosystems of Amazon, Cloudflare, Google, and Microsoft, respectively, and are designed to enhance the level of "appearing trustworthy." |
Behavioral Characteristics | Return from the U.S. regional visit 451 Unavailable for Legal Reasons / The region has been denied | Counter-espionage measures, geographical barriers, and strategies to evade U.S. law enforcement and researcher surveillance |
Model Symbol | 548 unique CNAMEs;332,000+ unique domains | This indicates that it is not a sporadic isolated scam operation, but rather a scalable fraud network capable of industrial-scale expansion. |
The original schematic diagrams and screenshots can be directly referenced from the CNAME schema diagram and frontend company interface in the Silent Push report, as well as the CNAME and function variable IOC list in the FBI FLASH. Since this round of public disclosures lacks reliable disclosed sample hashes or a complete one-to-one mapping of backend IPs, this report focuses its IOC analysis on root domains, spoofed domains, resolution chains, cloud ASN addresses, and operational touchpoints—objects more suitable for immediate interception by enterprise defense teams.
Response and Disposal Recommendations
For Enterprises:
l Upgrade Defense Strategy: Shift from blocking single domains to monitoringDomain Families + CNAME Chains + Cloud Landing Points. Implement CNAME chain backtracking and Certificate Transparency (CT) monitoring.
l Out-of-Band Verification: Require out-of-band verification for all payment, KYC, or investment requests. Never use links provided within a suspicious message thread.
l Unified Incident Response: Ensure the SOC, legal, and customer service teams share the same evidence repository to prevent siloed information.
l Forensic Preservation: Retain screenshots, full URLs, CNAME chains, and transfer records before performing "cleanup" deletions to aid in future legal recovery.
l Phishing-Resistant Authentication: Promote the use ofPasskeys (FIDO2)over traditional passwords to significantly reduce phishing success rates.
For Individuals:
l Immediate Cessation: If you suspect interaction with a scam, stop immediately. Contact your bank to freeze accounts or move remaining crypto assets to a completely new address.
l Official Channels Only: Change passwords only through official websites and revoke unknown sessions.
l Hardware Wallets: For crypto users, isolating high-value assets in hardware wallets is more effective than attempting post-theft recovery.
l Screen Sharing Warning: Never share your screen or install apps under the guidance of someone claiming to be "official" support over the phone or Google Meet.
Detection and Attribution Methods
For security analysts, this type of incident warrants investment inthree layers of attribution:
Layer 1: Domain and Infrastructure Layer:
l Analysts should use complaint URLs, page screenshots, or email headers to reverse-lookup domain registration dates, certificates (and certificate batches), HTML titles, favicons, and CNAME root domains.
l The goal is to perform multi-level resolution to identify shared intermediate domains and cloud landing points.
l FBI technical alerts and Silent Push link examples indicate that fraudulent infrastructure often "launders" itself using a "Customer Domain → Intermediate CNAME → Final A Record" structure.
Layer 2: Financial Layer:
l If cryptocurrency is involved, prioritize capturing the first-hop address, authorization records, transaction hashes, and timestamps.
l TRM notes that these fraud networks often transfer assets within48 hours; thus, preparing addresses, TxIDs, amounts, times, chains used, and exchange/wallet info before reporting is critical for freezing funds.
l Operation Atlantic's success in freezing over $12 million in one week was fundamentally due to the synchronized advancement of on-chain intelligence, victim notifications, and legal freezes.
Layer 3: Social Engineering Linkage Layer:
l Preserve original contact points, including SMS, social media DMs, call recordings, fake customer service numbers, scripts, original emails, screen-sharing invites, meeting links, and screenshots of any "official documents."
l Often, what links multiple fraud sites into a single syndicate is not a single IP, but shared script templates, ad copy, customer service playbooks, reconciliation sheets, and operational cadences.
l The Telegram contact points and front companies mentioned in the Silent Push report are examples of these "operational IOCs."
Legal Compliance and Recovery Considerations
Legal and Reporting
l For Enterprises: If a brand is being impersonated, firms should simultaneously pursue three avenues: law enforcement reporting, registrar/hoster takedown requests, and customer notifications.
l For Individuals: Report to local police or anti-fraud platforms immediately; those with crypto assets should also submit materials to exchanges, wallet providers, and on-chain reporting platforms.
l The experience of NCA, TRM, and Chainalysis in Operation Atlantic is clear: the earlier the report, the higher the chance of freezing funds before they exit an exchange.
Compliance and Due Diligence
l Financial institutions, trading platforms, payment companies, and major brand operators should integrate hoster/resolution chain/domain intelligence andsanctions screeninginto their third-party risk and anti-fraud processes.
l The Treasury Department's designation of FUNNULL illustrates that infrastructure providers themselves can become targets of sanctions and law enforcement.
l It is no longer sufficient to only monitor if users are being scammed; organizations must monitor if suspicious infrastructure is persistently appearing within their own ecosystems.
Recovery and Forensics
l Web-based Fraud: If the fraud was limited to a webpage (no device infection), prioritize account and financial loss mitigation, then preserve browser artifacts.
l Malicious Software: If a malicious app was installed or suspicious commands were executed, treat the device as potential evidence; prioritize imaging/exporting data before considering a factory reset.
l Crypto Wallets: Recovery should include revoking authorizations, migrating assets, creating a new wallet, refreshing passwords and MFA for all associated emails/exchanges, and checking browser extensions and notification permissions.
l Mobile Scams: Audit for abuse of accessibility services, SMS read/write permissions, and residual administrator privileges.
References
l Treasury Takes Action Against Major Cyber Scam Facilitator;https://home.treasury.gov/news/press-releases/sb0149
l Infrastructure Used to Manage Domains Related to Cryptocurrency Investment Fraud Scams between October 2023 and April 2025 ;https://www.fbi.gov/
l Post-Sanction Persistence: Triad Nexus' Operations Infrastructure Reborn as Threat Actor Distances Activity from FUNNULL CDN ;https://www.silentpush.com/blog/triad-nexus-funnull-2026/
l Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) ;https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/
l Passkeys are more secure than traditional ways to log in ;https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in
l Fraudsters targeting cryptocurrency stopped and $12 million frozen in NCA-led Operation Atlantic ;https://www.nationalcrimeagency.gov.uk/news/fraudsters-targeting-cryptocurrency-stopped-and-12-million-frozen-in-nca-led-operation-atlantic
l Satori Threat Intelligence Alert: Pushpaganda Manipulates Google Discovery Feeds with AI-Generated Content to Spread Malicious Notifications - HUMAN Security ;https://www.humansecurity.com/learn/resources/satori-threat-intelligence-alert-pushpaganda-manipulates-google-discovery-feeds-with-ai-generated-content-to-spread-malicious-notifications/
Insight Report Source: Global Cybersecurity Alliancehttps://www.gcsa.org
Get updates in your inbox
We respect your privacy. See our Privacy Policy