Recent research by Silent Push Threat Analysts, in partnership with Brian Krebs, has brought a sharp focus to the sprawling criminal infrastructure of the so-called Triad Nexus, which is operated through the FUNNULL Content Delivery Network (CDN).
This network, run by its administrator Lizhi Liu (also known as “Steve/Steven” Liu), is accused of facilitating hundreds of cyber-fraud and crypto-investment scam sites, resulting in over $200 million in losses to American victims.
However, crucially, FUNNULL’s persistence is enabled by the strategic abuse of Western cloud behemoths, such as Amazon Web Services and Microsoft Azure a practice known as “Infrastructure Laundering.”
At the heart of the Triad Nexus operation is the cunning use of “Infrastructure Laundering.” This tactic involves using stolen identities, fake businesses, or compromised payment methods to rapidly create new cloud accounts on reputable providers, such as AWS and Azure. Once onboard, the threat actor deploys scam websites or malicious infrastructure behind legitimate cloud IP addresses, making detection and blocking exponentially harder for defenders.
Despite the U.S. Treasury and FBI formally sanctioning FUNNULL and Liu in May 2025, enforcement across major cloud providers has been inconsistent.
Google appears to have taken proactive action, removing Liu’s YouTube channel and associated accounts. However, many accounts tied to Liu are still active on platforms provided by Microsoft, Amazon, Meta, and others, as detailed in Silent Push’s deep dive report.
The continued ability of sanctioned actors like Liu to leverage major cloud providers should serve as a wake-up call to the tech industry. Infrastructure Laundering not only fuels large-scale cybercrime but also complicates compliance with government sanctions.
Silent Push’s public report provides detailed indicators, usernames, emails, and domain names that organizations can use to proactively ban or monitor accounts tied to Liu and FUNNULL.
Until cloud providers adopt both automated and manual controls to detect and prevent Infrastructure Laundering, criminal networks like Triad Nexus will continue to weaponize the reputation and scale of Western tech giants against their own customers and national security interests.
PortSwigger has leveled up Burp Suite's scanning arsenal with the latest Active Scan++ extension, version…
Unit 42 researchers at Palo Alto Networks exposed serious flaws in the Model Context Protocol…
Polish police have arrested three Ukrainian men traveling through Europe and seized a cache of…
Google has launched its most significant Chrome update ever, embedding Gemini AI across the browser…
Attackers exploit this vulnerability through the router's web interface components, specifically "cgibin" and "hnap_main," by…
Security researchers have uncovered a severe flaw in Apache Tika, a popular open-source toolkit for…