- Company
Silent Push Inc. ©2025
Silent Push Threat Analysts have been tracking FUNNULL CDN and its use of infrastructure laundering since 2022. Our reporting began in May 2022 with our report on “Fake Trading Apps,” followed by our October 2024 expose, “Unveiling Triad Nexus: How FUNNULL CDN Facilitates Widespread Cyber Threats,” and then our January 2025 blog explaining “Infrastructure Laundering: Silent Push Exposes Cloudy Behavior Around FUNNULL CDN Renting IPs from Big Tech.” We have also provided additional coverage and analysis of FUNNULL CDN in our detailed reports created exclusively for our enterprise clients.
We have also hosted a webinar on Infrastructure Laundering and presented our FUNNULL research in 2025 at FIRST Monaco, B-Sides San Francisco, B-Sides Dublin, and numerous private briefings.
Last year, our analysts uncovered and exposed a sprawling network of domains routed through a China-based CDN service called FUNNULL. Our research revealed how this infrastructure quietly enabled cybercriminals, including groups linked to China, to leverage U.S. and other credible cloud providers for malicious activity.
The U.S. Department of the Treasury and the Federal Bureau of Investigation (FBI) issued a press release, “Treasury Takes Action Against Major Cyber Scam Facilitator” and an an FBI advisory report, “Infrastructure Used to Manage Domains Related to Cryptocurrency Investment Fraud Scams between October 2023 and April 2025,” respectively, on May 29, 2025, warning that FUNNULL is a major distributor of online scams.
These reports included critical new details that are now public:
The actions come months after our findings were published and reported by Brian Krebs of Krebs On Security, regarding how FUNNULL, “A sprawling network tied to Chinese organized crime gangs and aptly named ‘Funnull’ — highlights a persistent whac-a-mole problem facing cloud services.”
Cybercrime infrastructure is evolving fast—the cybersecurity community must adopt a proactive approach to detection. We’re also encouraged by other companies like Chainalysis writing up research about FUNNULL and sharing details, including key facts about FUNNULL’s connection to money laundering networks, writing, “Funnull had direct exposure to Huione Pay, for which the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) recently issued a finding and notice of proposed rulemaking (NPRM) identifying it as a primary money laundering concern.”
Register now for our free Community Edition to use all of the tools and queries mentioned in this blog.
Silent Push believes all domains associated with FUNNULL CDN and infrastructure laundering present some level of risk.
Our analysts construct Silent Push IOFA™ Feeds that provide a growing list of Indicators Of Future Attack™ data focusing on scams supported by this technique.
Silent Push Indicators Of Future Attack™ (IOFA™) Feeds are available as part of an Enterprise subscription. Enterprise users can ingest IOFA™ Feed data into their security stack to inform their detection protocols or use it to pivot across attacker infrastructure using the Silent Push Console and Feed Analytics screen.
Our team continues to track FUNNULL CDN and threat actors utilizing infrastructure laundering in its ever-evolving forms. We will report our findings to the security community as we identify new developments and other threat actors that exploit this practice.
We will also continue to share our research on threats we discover with law enforcement. If you happen to have any tips about threat actors participating in infrastructure laundering or engaging in other types of crime obfuscation activities, our team would love to hear from you.
Back in October 2024, our analysts uncovered and exposed a sprawling network of domains routed through a China-based CDN service called FUNNULL. Our research revealed how this infrastructure quietly enabled cybercriminals — including groups linked to Russia and North Korea — to leverage U.S. cloud providers for malicious activity.
Today, the U.S. Treasury sanctioned FUNNULL, labelling it a major distributor of online scams. This comes just months after our findings were published and reported by Brian Krebs, showing how FUNNULL-supported domains promoted gambling sites tied to Suncity Group — a name cited in a 2024 UN report for laundering money for North Korea’s Lazarus Group.
Cybercrime infrastructure is evolving fast — security teams must adapt a proactive approach to detection.
Resources:
Infrastructure Laundering On-Demand Webinar
Initial Silent Push FUNNULL public report
The Silent Push Chrome Extension is available to Enterprise users with an API key. Book a quick demo to see how upgrading can help you uncover attacker infrastructure smarter, faster, and with more confidence.