Funnull Resurfaces: Exposing RingH23 Arsenal and MacCMS Supply Chain Attacks

Reported 02 Mar 2026 by otx · Severity: medium

The report details the resurgence of the Funnull cybercriminal group, now utilizing a new arsenal called RingH23. It exposes their tactics, including compromising GoEdge CDN nodes, poisoning the MacCMS supply chain, and deploying sophisticated malware components like Badredis2s,