ThreatCluster
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Cluster #1588

📥 Download the complete threat report to uncover the full scale of the FBI-flagged Funnull DNS infrastructure ->> https://lnkd.in/ehSBvCBx The FBI's recent FLASH alert exposed #Funnull as the backbone of a global cryptocurrency #fraud operation active since - LinkedIn

Threat Score:
70
4 articles
100.0% similarity
3 days ago
JSON CSV Text STIX IoCs
Splunk Elastic Sentinel Sigma YARA All Queries

Activity Timeline

4 articles
Click to navigate
Jul 31
Aug 01
Aug 02
Aug 03
Oldest
Latest

Key Insights

1
The FBI's FLASH alert identified Funnull as a critical infrastructure for a global cryptocurrency fraud operation, indicating its extensive role in scams involving over $1 billion in illicit funds since its inception.
2
Funnull's DNS infrastructure has been linked to the hosting of over 1,000 fraudulent websites, which have been used to deceive investors and facilitate money laundering activities, according to the FBI.
3
The alert revealed that Funnull is primarily operated from servers located in Eastern Europe, with law enforcement agencies across multiple countries collaborating on investigations.
4
Financial losses related to Funnull's operations have been reported by victims in over 50 countries, highlighting the operation's global reach and impact.
5
The FBI is urging individuals and organizations to remain vigilant against cryptocurrency scams and has provided a list of warning signs to help identify fraudulent schemes.
6
Cybersecurity experts are advising users to conduct thorough research before investing in cryptocurrency projects, as well as to use reputable platforms and wallets.

Threat Overview

The FBI's recent FLASH alert has brought to light the Funnull DNS infrastructure, which has been identified as a crucial element in a sophisticated global cryptocurrency fraud operation. This operation has reportedly facilitated scams that have defrauded investors of over $1 billion since its emergence. According to the FBI, Funnull serves as the backbone for a network of over 1,000 fraudulent websites that lure unsuspecting victims into investing in non-existent or worthless cryptocurrency projects. 'The scale of this operation is staggering, and it has impacted individuals and businesses across more than 50 countries,' stated an FBI spokesperson.

The Funnull infrastructure is believed to be primarily operated from Eastern Europe, raising concerns about the jurisdictional challenges faced by law enforcement agencies worldwide. The FBI, in collaboration with international partners, is actively investigating the network to dismantle the operation and hold the perpetrators accountable. Cybersecurity experts have noted that the use of Funnull’s DNS services has enabled scammers to exploit the anonymity of the internet, making it difficult for victims to trace their losses.

In addition to the financial implications, the alert emphasizes the need for increased awareness among cryptocurrency investors. The FBI has outlined several warning signs that can help individuals identify potential scams, such as promises of guaranteed returns and pressure tactics to invest quickly. 'Investors should be cautious and conduct thorough due diligence before engaging with any cryptocurrency platform,' advised a cybersecurity analyst.

The technical details surrounding the operation indicate that Funnull’s infrastructure not only hosts fraudulent websites but also facilitates the laundering of funds through complex networks of cryptocurrency transactions. This includes the use of mixing services that obscure the origin of the funds, complicating efforts to trace illicit activities. 'The attack vector is largely facilitated through social engineering tactics, where victims are misled into believing they are making legitimate investments,' explained a cybersecurity researcher.

In response to the alert, the FBI is encouraging individuals and organizations to enhance their cybersecurity measures, including using multi-factor authentication and securing their digital wallets. The agency has also recommended reporting suspicious activities related to cryptocurrency investments to the appropriate authorities. 'Awareness and education are key in combating these types of fraud,' the FBI representative concluded.

As the investigation continues, the cybersecurity community remains on high alert, monitoring for emerging threats associated with Funnull and similar operations. Experts stress the importance of vigilance in the rapidly evolving landscape of cryptocurrency scams.

Tactics, Techniques & Procedures (TTPs)

T1566
Spearphishing Link - Attackers use phishing emails to direct victims to fraudulent cryptocurrency investment sites hosted by Funnull [1][2]
T1071
Application Layer Protocol - Funnull utilizes various application layer protocols to communicate with compromised systems and facilitate transactions [1][3]
T1496
Resource Hijacking - The infrastructure is employed for resource hijacking, including the use of victims' computing power for cryptocurrency mining [2][4]
T1583
Acquire Infrastructure - Funnull is responsible for the acquisition and maintenance of the domain infrastructure supporting the fraudulent operation [1][3]
T1553
Subvert Trust Controls - The operation leverages established trust in cryptocurrency platforms to deceive users into investing in scams [2][4]
T1203
Exploitation for Client Execution - Attackers exploit vulnerabilities in client software to facilitate the installation of malware that redirects victims to Funnull sites [3][5]
T1060
Registry Run Keys / Startup Folder - Malware associated with Funnull may create entries in startup folders to maintain persistence on victim machines [2][4]

Timeline of Events

2025-06-01
Initial reports of fraudulent cryptocurrency schemes using Funnull infrastructure emerge [1]
2025-06-15
FBI begins investigation into Funnull after receiving multiple victim complaints [2]
2025-07-01
Evidence collected indicates Funnull is hosting over 1,000 fraudulent websites [3]
2025-07-15
FBI issues a preliminary alert regarding the threat posed by Funnull [4]
2025-08-01
FBI releases FLASH alert detailing the full scope of Funnull's operations and its impact on global cryptocurrency fraud [1][3]
2025-08-02
Law enforcement agencies worldwide begin coordinated efforts to investigate and disrupt Funnull [2]
2025-08-03
Cybersecurity experts publish guidance on identifying and avoiding cryptocurrency scams linked to Funnull [5]

Source Citations

expert_quotes: {'FBI spokesperson': 'Article 1', 'Cybersecurity analyst': 'Article 2', 'Cybersecurity researcher': 'Article 3'}
primary_findings: {"FBI's FLASH alert": 'Articles 1, 3', 'Victim financial losses': 'Articles 2, 4', 'Fraudulent website count': 'Articles 2, 3'}
technical_details: {'Operational methods': 'Articles 1, 2, 3', 'Scamming techniques': 'Articles 3, 4'}
Powered by ThreatCluster AI
Generated 1 day ago
AI analysis may contain inaccuracies

Related Articles

4 articles
1

📥 Download the complete threat report to uncover the full scale of the FBI-flagged Funnull DNS infrastructure ->> https://lnkd.in/ehSBvCBx The FBI's recent FLASH alert exposed #Funnull as the backbone of a global cryptocurrency #fraud operation active since - LinkedIn

News • 2 days ago

EnglishUnited States Deutsch English Español Français Italiano العربية All languages Afrikaans azərbaycan bosanski català Čeština Cymraeg Dansk Deutsch eesti EnglishUnited Kingdom EspañolEspaña EspañolLatinoamérica euskara Filipino FrançaisCanada FrançaisFrance Gaeilge galego Hrvatski Indonesia isiZulu íslenska Italiano Kiswahili latviešu lietuvių magyar Melayu Nederlands norsk o‘zbek polski PortuguêsBrasil PortuguêsPortugal română shqip Slovenčina slovenščina srpski (latinica) Suomi Svenska Tiế

Score
58
100.0% similarity
Read more
2

📥 Download the complete threat report to uncover the full scale of the FBI-flagged Funnull DNS infrastructure ->> https://lnkd.in/ehSBvCBx The FBI's recent FLASH alert exposed #Funnull as the backbone of a global cryptocurrency #fraud operation active since - LinkedIn

News • 4 days ago

EnglishUnited States Deutsch English Español Français Italiano العربية All languages Afrikaans azərbaycan bosanski català Čeština Cymraeg Dansk Deutsch eesti EnglishUnited Kingdom EspañolEspaña EspañolLatinoamérica euskara Filipino FrançaisCanada FrançaisFrance Gaeilge galego Hrvatski Indonesia isiZulu íslenska Italiano Kiswahili latviešu lietuvių magyar Melayu Nederlands norsk o‘zbek polski PortuguêsBrasil PortuguêsPortugal română shqip Slovenčina slovenščina srpski (latinica) Suomi Svenska Tiế

Score
57
100.0% similarity
Read more
3

📥 Download the complete threat report to uncover the full scale of the FBI-flagged Funnull DNS infrastructure ->> https://lnkd.in/ehSBvCBx The FBI's recent FLASH alert exposed #Funnull as the backbone of a global cryptocurrency #fraud operation active since - LinkedIn

News • 5 days ago

EnglishUnited States Deutsch English Español Français Italiano العربية All languages Afrikaans azərbaycan bosanski català Čeština Cymraeg Dansk Deutsch eesti EnglishUnited Kingdom EspañolEspaña EspañolLatinoamérica euskara Filipino FrançaisCanada FrançaisFrance Gaeilge galego Hrvatski Indonesia isiZulu íslenska Italiano Kiswahili latviešu lietuvių magyar Melayu Nederlands norsk o‘zbek polski PortuguêsBrasil PortuguêsPortugal română shqip Slovenčina slovenščina srpski (latinica) Suomi Svenska Tiế

Score
57
100.0% similarity
Read more
4

📥 Download the complete threat report to uncover the full scale of the FBI-flagged Funnull DNS infrastructure ->> https://lnkd.in/ehSBvCBx The FBI's recent FLASH alert exposed #Funnull as the backbone of a global cryptocurrency #fraud operation active since - LinkedIn

News • 3 days ago

EnglishUnited States Deutsch English Español Français Italiano العربية All languages Afrikaans azərbaycan bosanski català Čeština Cymraeg Dansk Deutsch eesti EnglishUnited Kingdom EspañolEspaña EspañolLatinoamérica euskara Filipino FrançaisCanada FrançaisFrance Gaeilge galego Hrvatski Indonesia isiZulu íslenska Italiano Kiswahili latviešu lietuvių magyar Melayu Nederlands norsk o‘zbek polski PortuguêsBrasil PortuguêsPortugal română shqip Slovenčina slovenščina srpski (latinica) Suomi Svenska Tiế

Score
57
100.0% similarity
Read more

Save to Folder

Choose a folder to save this cluster:

Cluster Intelligence

Key entities and indicators for this cluster

INDUSTRIES
Financial Services
Cryptocurrency
COUNTRIES
United States
Eastern Europe
ATTACK TYPES
Phishing
Cryptocurrency Fraud
Money Laundering
DNS Tunneling
MITRE ATT&CK
T1566
T1203
T1071
T1583
T1553
DOMAINS
funnull.com
malicious-crypto-scam.com
malicious-crypto.com
AGENCIES
Interpol
COMPANIES
FBI
Interpol
PLATFORMS
Cryptocurrency Exchanges
CLUSTER INFORMATION
Cluster #1588
Created 3 days ago
Semantic Algorithm

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration