Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

Badredis2s

Badredis2s is a modular, plugin-based backdoor Trojan identified as the backdoor component of the RingH23 server-side compromise framework attributed in the reporting to the Funnull cybercriminal group, also known as Fangneng CDN. It is also referenced by the filenames ring04h_office_bin and office_bin. The malware targets Linux server environments compromised through RingH23 infection chains, including attacks in which a GoEdge CDN management node is first compromised and used to push payloads to downstream edge nodes over SSH, as well as campaigns linked to poisoned MacCMS update infrastructure that deploy related server-side malware. Badredis2s provides long-term remote access over AES-128-CBC encrypted WebSocket tunnels and is described as dynamically retrieving primary C2 addresses from Microsoft Azure Blob Storage. If primary connectivity is blocked, it falls back to DNS tunneling using the open-source iodine tool; reporting also states it uses WSS-over-TLS first and can use a hardcoded backup C2. Reported Badredis2s-associated C2 domains include linuxdistro[.]net, debianhacks[.]net, fedoraforums[.]net, ubuntucommands[.]com, ntp[.]asia, ntporg[.]com, sbindns[.]com, and plusedns[.]com. In the broader RingH23 campaign, Badredis2s operated alongside other Linux components including infect_init, download_init, the Badnginx2s malicious Nginx module, and the Badhide2s LD_PRELOAD userland rootkit. The overall activity was reported to affect CDN infrastructure and large numbers of streaming/movie-related sites, enabling malicious JavaScript injection, traffic redirection to gambling and pornographic sites, and cryptocurrency wallet address swapping.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Funnull

"The most technically advanced component is the Badredis2s backdoor (ring04h_office_bin), which communicates over AES-128-CBC encrypted WebSocket tunnels..."

via cyber security newscybersecuritynews.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1195Supply Chain CompromiseEvidence1

"Funnull pursued two separate infection routes. In the first, attackers compromised a GoEdge CDN management node... forcing all connected edge nodes to download and execute the RingH23 toolkit. In the second path, the group poisoned the official update channel of maccms.la... to deliver a malicious PHP backdoor."

Command and Control

3 techniques
T1071.001Web ProtocolsEvidence1

"...Badredis2s backdoor... communicates over AES-128-CBC encrypted WebSocket tunnels..."

T1071.004DNSEvidence1

"If the primary connection is blocked, it automatically falls back to DNS tunneling using the open-source iodine tool..."

T1568.002Domain Generation AlgorithmsEvidence1

"...with C2 addresses dynamically fetched from Microsoft Azure Blob Storage."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.