• News/
  • https://www.darkreading.com/cloud-security/chinese-infrastructure-laundering-abuses-aws-microsoft-cloud

Chinese 'Infrastructure Laundering' Abuses AWS, Microsoft Cloud

Dark Reading
·
Elizabeth Montalbano
·
Published Feb 4, 2025
·
Updated

Researchers have linked the China-based Funnull content delivery network (CDN) to a malicious practice they've dubbed "infrastructure laundering," in which threat actors exploit mainstream hosting providers such as Amazon Web Services (AWS) and Microsoft Azure. The activity involves threat actors operating "hosting companies" that rent IP addresses from these providers and then map them to their criminal websites. Researchers from Silent Push discovered the practice when they noticed that AWS and Microsoft Azure cloud hosting services are "often seen in large-scale use by threat actors," according to the recently published report. Further investigation led them to the discovery that Funnull CDN, a Chinese company that already has raised suspicions for other malicious activity, has been using this tactic to host a network of scam websites. Funnull has rented more than 1,200 IPs from AWS and nearly 200 IPs from Microsoft, according to Silent Push. While these have nearly all been taken down as of this writing, the company continuously acquires new IPs every few weeks, using them and then dumping them before defenders can identify the malicious activity. "While providers are consistently banning specific IP addresses used by the Funnull CDN, the pace is unfortunately not fast enough to keep up with processes being used to acquire the IPs," according to the report. The tactic is complicated to defend against because it blends malicious activities with legitimate Web traffic, maki...

Read full article

Affected Software

3 affected components
Amazon Web Services
Microsoft Azure
Funnull CDN
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the malicious practice of 'infrastructure laundering' involving the abuse of cloud services by Chinese threat actors.

2

What security implications are discussed?

The article highlights how threat actors exploit reputable cloud providers to hide their malicious activities, posing risks to data integrity and security.

3

What products or software are affected?

The affected products include Amazon Web Services, Microsoft Azure, and Funnull CDN.

4

Who are the main actors involved in this security issue?

The main actors involved are China-based threat actors utilizing the Funnull CDN for their malicious activities.

5

What is infrastructure laundering as described in the article?

Infrastructure laundering is a practice where malicious actors use legitimate cloud services to disguise their illegal activities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203