Economic sanctions have been leveled against Funnull Technology Inc., a Philippines-based infrastructure provider whose services have been exploited by cybercriminals running virtual currency investment scams commonly referred to as "pig butchering." The company's network has supported hundreds of thousands of fraudulent websites, with the U.S. government taking action after months of documented abuse.
The Treasury Department's action also targeted Liu Lizhi, a 40-year-old Chinese national who administers Funnull's operations. According to Treasury, "Americans lose billions of dollars annually to these cyber scams, with revenues generated from these crimes rising to record levels in 2024." The agency further stated that "Funnull has directly facilitated several of these schemes, resulting in over $200 million in U.S. victim-reported losses."
Treasury officials indicated that Funnull's infrastructure connects to the majority of virtual currency investment scam websites that have been reported to law enforcement. The company's role in facilitating pig butchering and related fraud schemes has resulted in documented financial harm exceeding $200 million to American victims.
How Pig Butchering Works
Pig butchering involves criminals posing as romantic interests online to manipulate victims into depositing money on fraudulent cryptocurrency trading platforms. Targets are gradually encouraged to invest increasing sums, with promises of substantial returns. When victims attempt to withdraw their funds, they discover the money has vanished. Scammers frequently demand additional "tax" payments on supposed cryptocurrency earnings before allowing access to invested capital—a condition that never results in fund recovery. Many victims have reported losses exceeding six figures through these schemes.
Funnull's Criminal Infrastructure
Security research firm Silent Push uncovered Funnull's role in October 2024, discovering that the company hosted numerous domains promoting gambling sites bearing the Suncity Group logo. A 2024 UN report had previously identified Suncity Group as involved in money laundering operations for Lazarus, the North Korean state-sponsored hacking group.

Silent Push characterized Funnull as a criminal content delivery network that routed traffic through automatically generated domain names and U.S.-based cloud providers before redirecting users to malicious or phishing websites. The FBI released technical documentation detailing the infrastructure used to manage malicious Funnull domains between October 2023 and April 2025.
When Silent Push re-examined Funnull's operations in January 2025, the firm discovered that many of the same Amazon and Microsoft cloud addresses identified as malicious in October remained active. Following the initial reporting, both companies pledged to eliminate Funnull's presence from their networks, but results have been uneven.
Silent Push researcher Zach Edwards reported that Microsoft has successfully removed Funnull infrastructure from its systems, but Amazon has struggled with the task. "Amazon is doing a terrible job — every day since they made those claims to you and us in our public blog they have had IPs still mapped to Funnull, including some that have stayed mapped for inexplicable periods of time," Edwards stated.
Amazon responded by noting that its AWS platform "actively counters abuse attempts" and has "stopped hundreds of attempts this year related to this group." The company added: "If anyone suspects that AWS resources are being used for abusive activity, they can report it to AWS Trust & Safety using the report abuse form here."
Why U.S. Cloud Infrastructure Attracts Criminals
U.S.-based cloud providers remain attractive targets for cybercriminal organizations because most entities hesitate to aggressively block traffic originating from American cloud networks, fearing collateral damage to legitimate services sharing the same infrastructure. Additionally, routing malicious traffic through U.S. cloud providers allows criminals to appear geographically closer to their victims, potentially circumventing location-based security controls implemented by financial institutions.
Related Sanctions: Stark Industries Solutions
Funnull was not the only criminal infrastructure provider sanctioned in May 2025. On May 20, the European Union imposed sanctions against Stark Industries Solutions, an ISP that emerged around the time of Russia's invasion of Ukraine and has functioned as a global proxy network concealing the origins of cyberattacks and disinformation campaigns targeting Russia's adversaries.
KrebsOnSecurity published an investigation in May 2024 examining Stark Industries Solutions, revealing that much of the malicious traffic traversing its network—including vulnerability scanning and password brute force attacks—was being routed through U.S.-based cloud providers. The reporting demonstrated Stark's extensive penetration of American ISP infrastructure and detailed how its co-founder had previously marketed "bulletproof" hosting services to Russian cybercrime forum users, promising to disregard abuse complaints and law enforcement inquiries.

Stark's co-founders are Moldovan brothers Ivan and Yuri Neculiti. Both denied involvement in cybercrime or participation in Russian disinformation or cyberattack operations. Nevertheless, the EU sanctioned both individuals alongside the company.
The EU determined that Stark and the Neculti brothers "enabled various Russian state-sponsored and state-affiliated actors to conduct destabilising activities including coordinated information manipulation and interference and cyber-attacks against the Union and third countries by providing services intended to hide these activities from European law enforcement and security agencies."
Source: Krebs on Security