“Infrastructure laundering” is Silent Push’s term for an alleged scheme in which an intermediary places criminal websites behind cloud-provider IP addresses and DNS mappings. In a January 2025 investigation, the security vendor said Funnull had rented more than 1,200 Amazon IP addresses and nearly 200 Microsoft IP addresses. Those are historical, vendor-reported figures—not a count of addresses active today—and they do not mean AWS or Microsoft operated the sites or knowingly enabled them.
What “infrastructure laundering” means
Silent Push uses “infrastructure laundering” to describe a pattern in which an intermediary obtains or rents infrastructure from a legitimate cloud provider, then maps customer websites to that infrastructure. The term describes the alleged effect: a site’s network path may appear to involve a familiar cloud service even when the site itself is fraudulent.
AWS disputed the implication that it acted as an intermediary to make abuse appear legitimate. The label is Silent Push’s terminology, not an independently established industry-wide category. The reporting describes alleged misuse of provider infrastructure; it does not establish that either provider knowingly hosted or operated the criminal sites.
How Funnull’s reported setup worked
In its January 30, 2025 report, Silent Push described Funnull as a content-delivery-network intermediary that rented cloud IP addresses and connected customer websites to them through DNS techniques, including CNAME records. A CNAME record points one hostname to another; in this reported pattern, DNS mappings helped associate websites with cloud addresses.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
The observed components—cloud IP addresses and DNS mappings—are distinct from claims about how individual accounts were obtained or who controlled them. Silent Push said fraudulent or stolen accounts were likely involved, while acknowledging that outsiders had limited visibility into account acquisition. AWS later told KrebsOnSecurity that linked accounts had used fraudulent methods to temporarily acquire infrastructure. That provider statement does not establish the acquisition history of every account in Silent Push’s analysis.
How many cloud IPs were involved?
Silent Push reported that Funnull had rented more than 1,200 Amazon IP addresses and nearly 200 Microsoft IP addresses in its January 2025 investigation. The report said nearly all of the identified addresses had been taken down by publication, while new addresses were appearing every few weeks. These are findings from that investigation, not a current active-address count.
Rank #2
Silent Push also identified more than 200,000 unique hostnames, with approximately 95% reportedly generated through domain-generation algorithms, according to Dark Reading’s account of the findings. These are vendor-reported figures about the activity under investigation, not a measure of how prevalent infrastructure laundering is overall.
What kinds of scams were reported?
Silent Push associated websites on the Funnull network with several types of alleged fraud:
Recommended Free Tools
Rank #3
- Investment scams and fake trading applications
- Retail phishing
- Pig-butchering scams
- Shell gambling websites that the vendor said were connected to money laundering as a service
These are Silent Push’s findings and allegations about sites linked to the network. They should not be read as evidence that AWS or Microsoft ran those sites.
What AWS and Microsoft said in 2025
In reporting published in 2025, the companies gave different responses. Dark Reading reported that AWS said all accounts known to be linked to the activity had been suspended and that there was no current risk requiring customer action. AWS also objected to the “infrastructure laundering” framing. Those comments describe AWS’s position at the time, not its status in 2026.
Rank #4
Dark Reading reported that Microsoft was looking into the activity. In separate contemporaneous reporting, Microsoft said it actively enforces acceptable-use policies when violations are detected and encouraged reports of suspicious activity. Those statements likewise do not establish Microsoft’s present-day status.
Why defenders cannot simply block cloud providers
Cloud addresses are shared by unrelated customers, so an IP address alone may not reliably identify a malicious website. NETSCOUT threat intelligence lead Richard Hummel told KrebsOnSecurity: “From a defenders point of view, you can’t wholesale block cloud providers, because a single IP can host thousands or tens of thousands of domains.” Blocking broad cloud-provider ranges can therefore disrupt legitimate services alongside malicious ones.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
The intermediary and DNS layers also complicate attribution and takedowns: investigators must connect domains, mappings, addresses, accounts, and operators rather than treating a cloud IP as proof of who runs a site. For defenders, that makes specific indicators and provider reporting more useful than blanket blocks.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What later reporting does—and does not—show
In April 2026, SecurityWeek reported that Silent Push linked the Triad Nexus cybercrime operation to continued infrastructure laundering involving Amazon, Cloudflare, Google, and Microsoft services, with account mules used to acquire accounts. This is a later reported example of the broader tactic. It does not show that the Funnull IP addresses identified in 2025 remained active.
The available reporting does not provide a current independently verified count of active Funnull addresses or a complete chronology of AWS and Microsoft actions after 2025. Readers should treat the 2025 counts and provider statements as historical, rather than as a live status report.
Quick Recap
Sources
- Silent Push, January 30, 2025 report on Funnull
- Dark Reading report on the activity and provider responses
- KrebsOnSecurity report, including AWS and NETSCOUT comments
- SecurityWeek report on Triad Nexus, April 2026
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

