Cyber Security News

RingH23 Threat Actors Target MacCMS and CDN Infrastructure with New Arsenal

Threat actors are abusing a new Linux-based toolkit dubbed RingH23 to silently compromise MacCMS-based video sites and hijack CDN infrastructure at scale, redirecting millions of users to gambling, pornography, and fraud platforms.​

Evidence shows Funnull has re-emerged with a fully owned attack framework that no longer parasitizes public CDNs, but actively compromises CDN nodes and content platforms.

The group’s upgraded operations blend server-side compromise, traffic hijacking, and behavioral targeting to maximize monetization from hijacked web traffic.

The campaign currently focuses on two parallel infection paths: poisoning MacCMS’s official update channel and compromising GoEdge-based CDN infrastructure.

Researchers link RingH23 to the Funnull cybercrime group, a Southeast Asia–centric “fraud cloud” previously sanctioned by the U.S. Treasury for enabling large-scale pig‑butchering scams and CDN poisoning attacks such as Polyfill.io and BootCDN.

In both cases, the end goal is the same: inject Funnull’s characteristic malicious JavaScript into high‑traffic sites and then selectively redirect visitors, mainly mobile users in the China time zone, to high‑value scam ecosystems.

How RingH23 Compromises CDN and MacCMS

On CDN infrastructure, attackers first breach a GoEdge management node and deploy an “infectinit” component with root privileges.

clondflare peaked on August 30, 2025, with 340,000 unique client visits in a single day. 

Client Trends (Source : XLab).

This binary validates a session token and a group ID via C2 at the client. 110.nz, then harvests edge node credentials from the GoEdge database before pushing a secondary “downloadinit” downloader over SSH to all CDN edge nodes.

Downloadinit queries the C2 for tailored payload URLs, deploys them under /var/adm, adds a udev persistence rule, and writes a malicious shared object (libutilkeybd.so) into /etc/ld.so.preload so the toolkit loads transparently on reboot.

The main payloads form a modular arsenal: “officebin” (Badredis2s) acts as a plugin-based backdoor with AES-encrypted C2 over WSS and DNS tunneling; “module.so” (Badnginx2s) is an Nginx filter module for JavaScript injection, download hijacking, and wallet address theft; “libutilkeybd.so” (Badhide2s) is an LD_PRELOAD rootkit that hides files, processes, and network connections while secretly loading the malicious Nginx module.

Persistence is reinforced through a rare but effective udev rule that launches RingH23 components whenever a network interface comes up, making clean-up difficult on busy servers.

On the application side, the maccms.la fork of MacCMS has reportedly been weaponized via its official update mechanism.

According to statistical data, the peak number of unique clients per day reached 580,000. Although the number has slightly declined, it currently remains at around 200,000.

Trend of Malicious JS Access (Source : XLab).

During the administrator’s first login after installation, MacCMS contacts update.maccms.la, which can serve a short‑lived ZIP package containing malicious PHP backdoors that inject Funnull’s JS loader into HTML templates and JavaScript assets.

The payloads employ strict time‑limited download URLs and caching headers to prevent later forensic retrieval, while view filters ensure every rendered page is eligible for infection under specific conditions such as mobile device access and external referrers.

Mitigations

Telemetry reveals just one typosquatted Cloudflare domain used in this operation, cdnjs.clondflare.com, reached an estimated 6.8 million users in a single day once extrapolated to the broader market.

In the maccms GitHub source code, the file application\admin\view_new\index\index.html contains an AJAX snippet that reports version information of maccms, PHP, and ThinkPHP to the remote server (update.maccms.la) to check for updates.

Upgrade Channel Poisoning (Source : XLab).

Thousands of movie and streaming sites have been identified with Funnull’s distinctive injected JavaScript, though dynamic injection means the true number of infected hosts is likely much higher.

The group’s CDN-facing infrastructure has also shifted to a suspicious new provider, CDN1.ai, whose GoEdge-based backend and poor operational hygiene suggest it may be a fresh Funnull-controlled front rather than a legitimate third‑party CDN.

During dynamic analysis, a large number of strings related to redis2s are printed, so we named it badredis2s.

office_bin (Source : XLab).

Defenders are urged to audit MacCMS deployments for malicious PHP files (such as application/extra/active.php and addons.php), remove poisoned update handlers, and consider migrating away from maccms.la entirely.

CDN operators should inspect GoEdge environments for RingH23 indicators, including unknown udev rules in /etc/udev/rules.d, references to libutilkeybd.so in /etc/ld.so.preload, and suspicious directories under /var/adm used to stage Nginx modules.

Where Badhide2s is present, setting the documented RING04H environment variable to the correct hash can temporarily disable hiding behavior, making it possible to fully enumerate and eradicate RingH23 components.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago