1 min read
Malware Campaign Exploits Microsoft Dev Tunnels
Originally Published March 31, 2025
7 min read
Cyber Florida SOCAP Team
:
Updated on August 17, 2026
Originally published: 02/11/2025
An emerging ransomware group known as FunkSec appeared in late 2024, compromising over 85 victims in December, more than any ransomware group that month. FunkSec is a new Ransomware-as-a-Service (RaaS) actor focusing on bolstering its malware using Artificial Intelligence (AI). These threat actors are said to be amateurs who demand unusually low ransoms and threaten to post victims' data on FunkSec’s data leak site (DLS). On this DLS, companies are listed as they become compromised. The site also hosts many malicious tools, including a free Distributed Denial of Service (DDoS) tool.
Some members of the FunkSec group have been involved in other hacktivist activities and claim to primarily target the United States and India. New Jersey Cybersecurity & Communications Integration Cell (NJCCIC), Recorded Future-– a leading threat intelligence platform, and Broadcom-–a semiconductor and software company, have all released reports urging organizations to stay ahead of the threat. They recommend implementing a defense-in-depth strategy using multiple layers of security, backing up systems, and keeping systems updated and patched.
Ransomware-as-a-service double extortion aims to place greater emphasis on paying the ransom, as it not only encrypts the data but also copies and exfiltrates it. Threat actors then threaten to leak this data if the ransom isn’t paid. In traditional ransomware, good backups of data can defeat ransomware and recover without payment
In December 2024, the FunkSec ransomware group appeared to have compromised its first 11 victims, sparking immediate interest among security researchers and news outlets. After further investigation of the malware, FunkSec V1.5, which originated from Algeria, showed many indications of AI use. The use of AI allowed the group to rapidly iterate on this ransomware and develop their tools, implying the attackers lack technical expertise. The group is said to seek recognition and visibility, appearing to demand ransoms as low as $10,000. Evidence also indicates that some of the leaked information posted on their DLS was recycled from previous hacktivist leaks, raising questions about its authenticity.
Although limited information is currently available, the exploit appears to begin with tactics defined in the MITRE ATT&CK framework, specifically T1193, T1203, and T1189. T1193 – Spear Phishing Attachment indicates that adversaries are using a series of spear-phishing campaigns to infect systems with ransomware by clicking email attachments containing malicious macros. T1203 – Exploitation of Client-Side Vulnerabilities allows an attacker to exploit a vulnerability in a system to gain access. T1189 – Drive-by Compromise allows an attacker to plant malicious objects on websites and in advertisements to lure victims into interacting with them. Once the user has initiated an access vector, the system becomes infected, all files are encrypted, and cannot be opened until the ransom is paid.
Previous ransomware campaigns involving such exploitation raise major concerns, and this attack highlights a new threat, as the use of AI clearly elevates their severity. FunkSec is found to use AI in creating a malicious DDoS tool, including redundant code that calls the binaries multiple times, and to use extensive, perfect English comments. FunkSec’s broad adaptation across many attack vectors makes it capable of exploiting many people and organizations through rapid iterations of this malware and evading defenses. These attacks could bring down companies across all industries.
Organizations are strongly urged to maintain proper security practices. These practices should include security awareness training, applying the latest patches, and monitoring for indicators of compromise (IoC). Furthermore, safe searching practices should be enforced, urging the download of materials only from official and trustworthy channels. Failure to follow these procedures could result in severe disruptions and data breaches.
| Type | Indicator |
|---|---|
| SHA-256 Hash |
c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c |
| SHA-256 Hash |
66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd |
| SHA-256 Hash |
dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac |
| SHA-256 Hash | b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb |
| SHA-256 Hash | 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd |
| SHA-256 Hash | e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22 |
| SHA-256 Hash | 20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d |
| SHA-256 Hash | dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966 |
| SHA-256 Hash | 7e223a685d5324491bcacf3127869f9f3ec5d5100c5e7cb5af45a227e6ab4603 |
| Source Code File | *ransomware.rs* |
| File Extension | (.funksec) |
| FunkSec Scorpion Domain | hxxps://miniapps[.]ai/funksec |
| FunkSec Malware Hosting | hxxps://gofile[.]io/d/8FOSeP |
| FunkSec DLS | hxxp://funknqn44slwmgwgnewne6bintbooauwkaupik4yrlgtycew3ergraid[.]onion/ |
| FunkSec DLS | hxxp://funkiydk7c6j3vvck5zk2giml2u746fa5irwalw2kjem6tvofji7rwid[.]onion/ |
Associated Threat Actors:
Scorpion: Prominent member of FunkSec, uses multiple aliases such as DessertStorm.
El_farado: Promotes FunkSec, making sure this group stays visible.
Associated Hacktivist Groups:
-Ghost Algeria: Made evident in a ransom note similar to FunkSec’s.
-Cyb3r Fl00d: Old group based on a screenshot.
Artificial Intelligence (AI) Indicators:
-Very well structured and formatted comments and code, as well as the publication of an AI chatbot named Scorpion.
Dulaunoy, A., Fafner, & Harper, T. (n.d.). RansomLook . RansomLook. https://www.ransomlook.io/
Antoniuk, D. (2025, January 10). New amateurish ransomware group FunkSec using AI to develop malware. Cyber Security News | The Record. https://therecord.media/funksec-ransomware-using-ai-malware
Arghire, I. (2025, January 13). Emerging FUNKSEC ransomware developed using AI. SecurityWeek. https://www.securityweek.com/emerging-funksec-ransomware-developed-using-ai/
Check Point Research. (2025, January 9). Meet FunkSec: A new, surprising ransomware group, powered by ai. Check Point Blog. https://blog.checkpoint.com/research/meet-funksec-a-new-surprising-ransomware-group-powered-by-ai/
Check Point Software. (2024, February 8). What is double extortion ransomware?. Check Point Software. https://www.checkpoint.com/cyber-hub/ransomware/what-is-double-extortion-ransomware/
FunkSec RaaS Dominates the Ransomware Landscape in December. Cyber.nj.gov. (2025, January 16). https://www.cyber.nj.gov/Home/Components/News/News/1574/214?rq=emotet
FUNKSEC ransomware. Broadcom Inc. (2025, January 9). https://www.broadcom.com/support/security-center/protection-bulletin/funksec-ransomware
Hollingworth, D. (2025, January 14). Inside FunkSec, the self-taught hackers supported by Ai Code. Cyber Daily. https://www.cyberdaily.au/security/11575-inside-funksec-the-self-taught-hackers-supported-by-ai-code
Infosecurity Magazine. (2025, January 13). New Ransomware Group uses AI to develop Nefarious Tools. Infosecurity Magazine. https://www.infosecurity-magazine.com/news/new-ransomware-group-uses-ai/
Lakshmanan, R. (2025, January 11). Ai-driven ransomware FUNKSEC targets 85 victims using double extortion tactics. The Hacker News. https://thehackernews.com/2025/01/ai-driven-ransomware-funksec-targets-85.html
LevelBlue – Open Threat Exchange. LevelBlue Open Threat Exchange. (n.d.). https://otx.alienvault.com/pulse/678127dbf6bb4958da4254cd/
MalwareBazaar Database-funksec. MalwareBazaar. (2025). https://bazaar.abuse.ch/browse/tag/funksec/
Meskauskas, T. (2025, January 13). Funklocker (FunkSec) ransomware. FunkLocker (FunkSec) Ransomware – Decryption, removal, and lost files recovery (updated). https://www.pcrisk.com/removal-guides/31853-funklocker-funksec-ransomware
Mitre ATT&CK®. MITRE ATT&CK®. (n.d.). https://attack.mitre.org/
Price, A. (2024, December 4). Take me down to FUNKSEC town: Funksec ransomware DLS Emergence . CYJAX. https://www.cyjax.com/resources/blog/take-me-down-to-funksec-town-funksec-ransomware-dls-emergence/
Reynolds, I. (2025, January 11). FUNKSEC: The emergence of ai-driven ransomware threats. SecureTeam. https://secureteam.co.uk/news/funksec-the-emergence-of-ai-driven-ransomware-threats/
Stcpresearch. (2025, January 10). FunkSec – alleged top ransomware group powered by ai. Check Point Research. https://research.checkpoint.com/2025/funksec-alleged-top-ransomware-group-powered-by-ai/
Tag funksec. ThreatFox. (n.d.). https://threatfox.abuse.ch/browse/tag/funksec/
Check Point Research. (2025, January 15). FunkSec: The rising yet controversial ransomware threat actor dominating December 2024. Check Point Blog. https://blog.checkpoint.com/research/funksec-the-rising-yet-controversial-ransomware-threat-actor-dominating-december-2024/
Contributing Security Analysts: Timothy Kircher
1 min read
Originally Published March 31, 2025
1 min read
Originally Published March 4, 2025
1 min read
Originally Published December 8, 2025