Full Report
The FBI provided details of Funnull’s malicious activities, selling infrastructure to criminal groups to facilitate cryptocurrency fraud in the US
Analysis Summary
# Threat Actor: Funnull Technology Inc. (Infrastructure Provider)
## Attribution & Identity
The FBI has flagged **Funnull Technology Inc.**, a company based in the **Philippines**, for providing the technology infrastructure supporting a majority of Cryptocurrency Investment Fraud (CIF) scams targeting US victims. This entity is not the scammer group itself but an enabler/facilitator.
## Activity Summary
Funnull Technology Inc. has been tracked by the FBI for malicious activities between **October 2023 and April 2025**.
The company's primary role is to acquire IP addresses and other internet facilities from legitimate US providers and then resell this infrastructure to cybercriminals operating CIF scams. These schemes have resulted in over **$200 million** in US victim-reported losses, with average losses exceeding **$150,000 per victim**.
## Tactics, Techniques & Procedures
The article describes the *scammers'* TTPs that Funnull facilitates, not necessarily Funnull's internal TTPs, although Funnull's main TTP is infrastructure reselling:
- Providing hosting services and other internet infrastructure to cybercriminals.
- Acquiring legitimate IP addresses and facilities and transferring them to illicit actors.
- Facilitating Cryptocurrency Investment Fraud (CIF) scams, also known as "pig butchering" or "romance baiting," where perpetrators pose as romantic partners/friends to build trust before directing victims to fraudulent investment platforms.
- **MITRE ATT&CK IDs (Inferred from Scam Type):** Related to Social Engineering/Impersonation (T1562.001 - Impersonation), Command and Control (T1071.001 - Application Layer Protocol - used for C2 to fake investment platforms).
## Targeting
- **Sectors:** Victims targeted by the scams include individuals investing in cryptocurrency, categorized under Cybercrime/Financial Fraud. (The direct victims are individuals, not specific corporate sectors, in this context.)
- **Geography:** Victims are primarily located in the **US**. The threat actor infrastructure provider (Funnull) is based in the **Philippines**.
- **Victims:** General US victims of CIF scams. Specific organizations were not named.
## Tools & Infrastructure
- **Malware families used:** Not explicitly mentioned, as the focus is on the infrastructure platform.
- **Infrastructure (C2, domains, IPs - defang URLs):**
- **Provider:** Funnull Technology Inc. (Philippines)
- **Facilitated Infrastructure:** IP addresses and internet facilities acquired from legitimate US providers.
## Implications
The involvement of a recognized, operational technology company like Funnull in supplying infrastructure for massive financial crimes significantly elevates the threat. It demonstrates a sophisticated monetization channel for large-scale illicit operations, making attribution and disruption difficult as the infrastructure often appears legitimate or originates from trusted supply chains (US-based providers). The large aggregate losses indicate a high-impact, financially motivated threat.
## Mitigations
- **For Internet Service Providers (ISPs):** Take action to mitigate Funnull’s continued activities, likely involving revoking access or identifying sourced IPs.
- **General Defense:** Increased awareness of Cryptocurrency Investment Fraud (CIF) / "pig butchering" scams, focusing on verifying the legitimacy of investment platforms introduced by romantic or social contacts.