A new cybercriminal campaign, linked to the notorious Funnull group, has targeted both Content Delivery Networks (CDNs) and the open-source MacCMS system.
The attack, dubbed RingH23, has demonstrated the group’s evolving tactics and infrastructure, showing a high level of sophistication.
RingH23 comprises several malicious tools aimed at compromising CDN nodes, injecting malicious JavaScript into websites, and performing stealthy supply-chain poisoning attacks.
How The Attack Unfolds
The attack begins with exploiting vulnerabilities in the CDN and CMS infrastructure.
Funnull’s RingH23 toolkit leverages multiple infection vectors, including the compromise of a GoEdge CDN management node and poisoning the official update channels of MacCMS, an open-source content management system used for video streaming sites.
Once the attackers have access, they deploy a multi-stage infection cycle. The attackers use a downloader, identified as download_init, to retrieve and execute malicious payloads, including backdoors, Nginx modules, and userland rootkits.

These components then establish persistence on infected servers, enabling further exploitation.
One of the most concerning aspects of the attack is the injection of malicious JavaScript into web pages that redirects visitors to gambling or pornographic websites, thereby monetizing stolen traffic.

Key Components Of The RingH23 Toolkit
- Badredis2s: A backdoor Trojan that provides the attackers with persistent control over the infected devices. It uses AES encryption for network communication and features dual-layer redundancy for Command-and-Control (C2) acquisition, using both WebSocket and DNS tunneling.
- Badnginx2s: This malicious Nginx module is designed for traffic hijacking. It silently modifies website content to redirect visitors, replace cryptocurrency wallet addresses, and even inject ads or videos. Its primary focus is monetizing traffic by tricking users into visiting malicious sites.
- Badhide2s: A userland rootkit that hides the activities of the attackers, ensuring that their presence remains undetected by common security tools. It hides files, processes, and network connections, making the malware difficult to trace.
- udev-based Persistence: Using udev rules for persistence is a novel approach. The attackers install specific rules on compromised Linux servers, ensuring that their malicious payloads execute automatically after system reboots.

According to Qianxin research, this campaign has already shown signs of large-scale impact. The malicious JavaScript injected into websites has been detected on 10,748 IP addresses, many of which are streaming and movie-related.
These websites have been compromised to redirect users, mainly in China, to illicit gambling and adult websites.
The C2 infrastructure linked to this attack has achieved a significant reach, with some domains registering millions of unique client visits.
The return of Funnull in this upgraded form signals the continued resilience of cybercriminal groups. Given their increasing sophistication and the extensive damage they have caused, maintaining robust defenses and constant vigilance is more critical than ever.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.