{"id":12127,"date":"2026-04-15T10:03:42","date_gmt":"2026-04-15T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/15\/funnull-linked-triad-nexus-resurfaces-with-175-rotating-cname-domains-and-global-scam-portals\/"},"modified":"2026-04-15T10:03:42","modified_gmt":"2026-04-15T10:03:42","slug":"funnull-linked-triad-nexus-resurfaces-with-175-rotating-cname-domains-and-global-scam-portals","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/15\/funnull-linked-triad-nexus-resurfaces-with-175-rotating-cname-domains-and-global-scam-portals\/","title":{"rendered":"FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals"},"content":{"rendered":"<p>    FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A cybercriminal group tied to the FUNNULL Content Delivery Network has made a calculated return with a far more sophisticated and evasive infrastructure. <\/p>\n<p>Known as Triad Nexus, the group has rebuilt its global fraud operation following U.S. Treasury sanctions, deploying over 175 randomly rotating CNAME domains to power a sprawling network of scam portals that target victims across multiple countries.<\/p>\n<p>Triad Nexus is not a new player in the threat landscape. The group is deeply rooted in organized criminal networks across Asia and has been actively running investment scams, money laundering operations, and illegal gambling platforms since at least 2022. <\/p>\n<p>Its earlier campaigns relied heavily on the FUNNULL CDN as the primary backbone, enabling fast delivery of fraudulent websites designed to look exactly like trusted global brands. <\/p>\n<p>What changed after the U.S. sanctions was not the group\u2019s criminal intent \u2014 it was their method of concealment.<\/p>\n<p>Following the May 2024 federal sanctions, the group rapidly pivoted to what researchers describe as \u201cinfrastructure laundering.\u201d <\/p>\n<p>Rather than relying solely on low-reputation servers, Triad Nexus began hijacking legitimate enterprise cloud accounts at major providers including Amazon Web Services, Cloudflare, Google, and Microsoft. <\/p>\n<p>By routing malicious traffic through these trusted platforms, the group created an appearance of legitimacy that made its fake portals far harder to detect or block. <\/p>\n<p><a href=\"https:\/\/www.silentpush.com\/blog\/triad-nexus-funnull-2026\/\" id=\"https:\/\/www.silentpush.com\/blog\/triad-nexus-funnull-2026\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Silent Push analysts and researchers identified this tactical shift<\/a> as a major evolution, noting that the group had abandoned stable CNAME domains in favor of a rotating pool of over 175 randomly generated CNAME domains \u2014 each one connecting clusters of fraudulent websites to stolen or illicitly acquired IP addresses.<\/p>\n<p>The scale of the fraud is staggering. Triad Nexus has been linked to over one billion dollars in reported victim losses, with individual losses averaging around $47,000. <\/p>\n<p>The group primarily runs \u201cpig butchering\u201d scams, where victims are manipulated over weeks or months into investing large sums into fake <a href=\"https:\/\/cybersecuritynews.com\/6-trends-shaping-cryptocurrency-and-blockchain-in-2025\/\" id=\"88651\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency platforms<\/a>. <\/p>\n<p>Their catalog of fraudulent portals includes pixel-perfect clones of luxury brands like Tiffany, Cartier, and Chanel, financial platforms like Western Union and MoneyGram, and banking portals falsely tied to Wells Fargo, Goldman Sachs, and Bank of America.<\/p>\n<p>To avoid law enforcement attention after the sanctions, the group also launched a series of \u201cclean\u201d front companies \u2014 entities with professional branding and fabricated operating histories designed to manufacture trust among unsuspecting users. <\/p>\n<p>One particularly revealing example is a fake CDN provider operating as cdnbl.com, which falsely claims to have served clients since 2007. Domain registration records confirm it was only created in March 2024, exposing the deception at its core.<\/p>\n<h2 class=\"wp-block-heading\" id=\"geographic-evasion-and-the-rotating-cname-infrastr\"><strong>Geographic Evasion and the Rotating CNAME Infrastructure<\/strong><\/h2>\n<p>One technically alarming aspect of Triad Nexus\u2019s rebuilt operation is its deliberate use of multi-layered CNAME chains to hide the true destination of its traffic. <\/p>\n<p>A CNAME, or Canonical Name record, is a DNS entry that redirects one domain to another. Standard security tools typically only follow a single step in this chain, meaning the real final endpoint often goes completely undetected.<\/p>\n<p>Triad Nexus actively exploits this blind spot. Its infrastructure routes traffic through multiple intermediate CNAME domains \u2014 sometimes three or four layers deep \u2014 before landing on a final IP address hosted on a reputable enterprise cloud platform.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiavJjPWJFOfjGg-AY-gm5RCGzN6bm_Wsi5E0p5BpGjtASIAOAkb1PgHleNw2CQbi_xTPHWeAJEi0WkRnFlsa49qYgr2nJr9SgvUWtkUY6gdo6dBcmJoR4j7QT7Ph9rWUgZO7qo_j7XuqW52eVMzga6OR_Byf0GKLRLC5Pf2F2F2uF4X0PHkr54fgs2dMs\/s16000\/CNAME%2520chain%2520between%2520an%2520IP%2520and%2520a%2520client%2520domain%2520cluster%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"CNAME chain between an IP and a client domain cluster (Source - Silent Push)\"><figcaption class=\"wp-element-caption\">CNAME chain between an IP and a client domain cluster (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>This multi-layered redirection makes it extremely difficult for automated <a href=\"https:\/\/cybersecuritynews.com\/best-fraud-detection-tools\/\" id=\"13681\" target=\"_blank\" rel=\"noreferrer noopener\">detection tools<\/a> to trace traffic back to its true origin. <\/p>\n<p>To further avoid oversight, the group has placed a deliberate U.S. block across many of its portals, displaying an error that reads \u201cThe region has been denied\u201d to American visitors, while simultaneously expanding its scam operations into Spanish, Vietnamese, and Indonesian markets to keep its fraud profits flowing.<\/p>\n<p>Organizations are strongly advised to move beyond reactive security measures. <a href=\"https:\/\/cybersecuritynews.com\/security-teams-shrink-as-automation-rises\/\" id=\"100650\" target=\"_blank\" rel=\"noreferrer noopener\">Security teams<\/a> should adopt CNAME chain analysis capabilities, monitor for newly registered lookalike domains, enforce strict DNS resolution policies, and maintain deep visibility across all network layers to detect and disrupt threats of this nature before they reach end users.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/funnull-linked-triad-nexus-resurfaces\/\">FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/funnull-linked-triad-nexus-resurfaces\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals A cybercriminal group tied to the FUNNULL Content Delivery Network has made a calculated return with a far more sophisticated and evasive infrastructure. Known as Triad Nexus, the group has rebuilt its global fraud operation following U.S. Treasury sanctions, deploying over 175 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12127","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12127"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12127"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12127\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}