FUNNULL-linked infrastructure used by the Triad Nexus scam syndicate has re-emerged at scale, with researchers now tracking more than 175 rotating CNAME domains designed to launder infrastructure and evade takedowns continuously.
The network’s return signals that post‑sanctions pressure has degraded, but not dismantled, one of the most profitable “pig-butchering” and virtual currency fraud ecosystems on the internet.
Triad Nexus Rebuilds Its Fraud Engine
Silent Push researchers attribute more than $200 million in reported losses to Triad Nexus, with average victim losses of around $150,000 per case, underscoring the high-conversion nature of its investment and crypto scam funnels. Despite U.S.
Treasury sanctions against FUNNULL in 2025 and FBI/IC3 warnings, the group has quietly rebuilt its global fraud engine, refocusing on emerging markets while retaining the capacity to hit Western consumers and enterprises.
The most significant technical shift since sanctions is Triad Nexus’s move from a small set of stable FUNNULL CNAMEs to a large, rapidly rotating pool of more than 175 randomly generated CNAME domains.
Instead of easily fingerprintable hostnames referencing “funnull”, “fn”, or “fc”, the group now favors opaque labels like kanejwo[.]com and cdn899[.]com, smaooe[.]com, and ddge[.]ru to connect clusters of client scam domains to laundered IP space across CTG Server, Amazon, Cloudflare, Microsoft, and other providers.

A typical malicious chain observed by Silent Push now follows a multi‑hop pattern: a disposable client domain points to a first intermediary CNAME record, then a second, and finally resolves to an A record hosted on a compromised or fraudulently obtained cloud IP, often within AS152194.

According to Silent Push, standard reactive techniques single‑hop DNS lookups, static IP or domain blocklists, and case‑by‑case takedowns cannot keep pace with this automated infrastructure‑as‑code model.
In response, the company has released a dedicated CNAME Chain Lookup capability that allows defenders to submit any known CNAME and retrieve the full set of chains, client domains, and mapped IPs associated with it over time.
By exposing the entire CNAME path rather than just the next link, the tool is designed to help security teams rebuild Triad Nexus clusters, track rotations across CDNs and ASNs, and coordinate preemptive disruption before new scam sites go fully live.
For Silentpush enterprises, the return of FUNNULL‑linked Triad Nexus activity reinforces that brand protection, DNS‑layer telemetry, and high‑fidelity infrastructure mapping are now core requirements, not optional add‑ons, for protecting customers from high‑value fraud.
Security teams are being urged to monitor for look‑alike domains, CNAME chains terminating in suspicious CDNs or ASNs, and unexplained traffic surges from regions now favored by the group, while sharing indicators with trusted threat‑intel partners to raise global detection coverage.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.



