Chinese ‘Infrastructure Laundering’ Abuses AWS, Microsoft Cloud www.darkreading.com/cloud-sec…

Researchers have linked the China-based Funnull content delivery network (CDN) to a malicious practice they’ve dubbed “infrastructure laundering,” in which threat actors exploit mainstream hosting providers such as Amazon Web Services (AWS) and Microsoft Azure. The activity involves threat actors operating “hosting companies” that rent IP addresses from these providers and then map them to their criminal websites.

Researchers from Silent Push discovered the practice when they noticed that AWS and Microsoft Azure cloud hosting services are “often seen in large-scale use by threat actors,” according to the recently published report. Further investigation led them to the discovery that Funnull CDN, a Chinese company that already has raised suspicions for other malicious activity, has been using this tactic to host a network of scam websites.

Funnull has rented more than 1,200 IPs from AWS and nearly 200 IPs from Microsoft, according to Silent Push. While these have nearly all been taken down as of this writing, the company continuously acquires new IPs every few weeks, using them and then dumping them before defenders can identify the malicious activity.

*****
Written on