7 min read

FunkSec: A Top Ransomware Group Leveraging AI

FunkSec: A Top Ransomware Group Leveraging AI

Originally published: 02/11/2025

I. Targeted Entities

  • Government
  • Healthcare
  • Manufacturing
  • Media
  • Technology

II. Introduction

An emerging ransomware group known as FunkSec appeared in late 2024, compromising over 85 victims in December, more than any ransomware group that month. FunkSec is a new Ransomware-as-a-Service (RaaS) actor focusing on bolstering its malware using Artificial Intelligence (AI). These threat actors are said to be amateurs who demand unusually low ransoms and threaten to post victims' data on FunkSec’s data leak site (DLS). On this DLS, companies are listed as they become compromised. The site also hosts many malicious tools, including a free Distributed Denial of Service (DDoS) tool.

Some members of the FunkSec group have been involved in other hacktivist activities and claim to primarily target the United States and India. New Jersey Cybersecurity & Communications Integration Cell (NJCCIC), Recorded Future-– a leading threat intelligence platform, and Broadcom-–a semiconductor and software company, have all released reports urging organizations to stay ahead of the threat. They recommend implementing a defense-in-depth strategy using multiple layers of security, backing up systems, and keeping systems updated and patched.

Ransomware-as-a-service double extortion aims to place greater emphasis on paying the ransom, as it not only encrypts the data but also copies and exfiltrates it. Threat actors then threaten to leak this data if the ransom isn’t paid. In traditional ransomware, good backups of data can defeat ransomware and recover without payment

III. Additional Background Information

In December 2024, the FunkSec ransomware group appeared to have compromised its first 11 victims, sparking immediate interest among security researchers and news outlets. After further investigation of the malware, FunkSec V1.5, which originated from Algeria, showed many indications of AI use. The use of AI allowed the group to rapidly iterate on this ransomware and develop their tools, implying the attackers lack technical expertise. The group is said to seek recognition and visibility, appearing to demand ransoms as low as $10,000. Evidence also indicates that some of the leaked information posted on their DLS was recycled from previous hacktivist leaks, raising questions about its authenticity.

Although limited information is currently available, the exploit appears to begin with tactics defined in the MITRE ATT&CK framework, specifically T1193, T1203, and T1189. T1193 – Spear Phishing Attachment indicates that adversaries are using a series of spear-phishing campaigns to infect systems with ransomware by clicking email attachments containing malicious macros. T1203 – Exploitation of Client-Side Vulnerabilities allows an attacker to exploit a vulnerability in a system to gain access. T1189 – Drive-by Compromise allows an attacker to plant malicious objects on websites and in advertisements to lure victims into interacting with them. Once the user has initiated an access vector, the system becomes infected, all files are encrypted, and cannot be opened until the ransom is paid.

Previous ransomware campaigns involving such exploitation raise major concerns, and this attack highlights a new threat, as the use of AI clearly elevates their severity. FunkSec is found to use AI in creating a malicious DDoS tool, including redundant code that calls the binaries multiple times, and to use extensive, perfect English comments. FunkSec’s broad adaptation across many attack vectors makes it capable of exploiting many people and organizations through rapid iterations of this malware and evading defenses. These attacks could bring down companies across all industries.

Organizations are strongly urged to maintain proper security practices. These practices should include security awareness training, applying the latest patches, and monitoring for indicators of compromise (IoC). Furthermore, safe searching practices should be enforced, urging the download of materials only from official and trustworthy channels. Failure to follow these procedures could result in severe disruptions and data breaches.

IV. MITRE ATT&CK

  • T1193 – Spear Phishing Attachment
    FunkSec V1.5 can gain initial access through a spear phishing campaign. These campaigns can take various forms, such as an email containing a malicious attachment or a malicious link, as outlined in 001- Phishing: Spear Phishing Link. This allows attackers to gain access to the system after a download has completed, a file has been opened, or a link has been clicked.
  • T1203 – Exploitation for Client Execution
    The adversary can also exploit vulnerabilities within applications and software to run their malicious executables.
  • T1189 – Drive-by Compromise
    These threat actors also leverage torrent websites that impersonate legitimate tools to trick users into downloading ransomware and gaining initial access. This allows attackers to compromise a system by having a user visit a website during normal browsing. This tactic requires the exploitation of an established website or the creation of a new website to lure victims in.
  • T1204 – User Execution
    Based on the limited information provided, this ransomware group requires user execution of its malware via various vectors. Once the user opens a file, accesses a file on a website, or interacts with a malicious advertisement, the exploit will occur.
  • T1059 – Command and Scripting Interpreter
    Once FunkSec V1.5 is executed, the device's wallpaper will turn black, and encryption of each file will commence, while a README note is added notifying the user that the victim’s organization has been attacked, resulting in all files being encrypted and stolen. The malware recursively encrypts all directories using WriteFileEx to write the encrypted content back to disk and CryptGenRandom to generate cryptographic keys or initialization vectors. Refusal to pay or tampering with the files or network, such as contacting the authorities or using anti-virus (AV) tools, will result in exfiltrated content being sold.
  • T1071 – Application Layer Protocol
    As the malware moves through each letter drive, recursively encrypting all files and directories, a ransom note appears on the desktop, including a payment link. This indicates the use of application-layer protocols such as HTTPS and Command & Control, used to transfer payments by accessing hxxps://getsession[.]org with a given session key.
  • T1053 – Scheduled Task/Job
    Within this code, there are also multiple hard-coded constants, such as “RansomwarePassword123,” used during encryption, which can indicate scheduled or timed tasks to ensure persistence.
  • T1548 – Abuse Elevation Control Mechanism
    This malware attempts to check for elevated privileges by executing the net session. If not successful, it tries to relaunch itself with elevated privileges using “start-process -wait Verb runas -filepath ‘%~nx0’ -ArgumentList ‘<arguments>’”.
  • T1562.001 – Impair Defenses: Disable or Modify Tools
    Once the ransomware has elevated privileges,  it moves to evade defenses by disabling all security mechanisms on the device. These security mechanisms include Windows Defender, security event logging, application event logging, and disabling restrictions placed by PowerShell execution policy. These actions are executed via commands such as “Set-MpPreference -DisableRealtimeMonitoring $true” and “Set-ExecutionPolicy Bypass -Scope Process -Force”. These techniques allow for a smaller file-detection footprint, making them harder to identify during data exfiltration.
  • T1486 – Data Encrypted for Impact
    While all security mechanisms are disabled, the Rust-based malware attempts to encrypt all files and append the file type “.funksec”. Typical ransomware calls a binary only once, whereas the FunkSec V1.5 code repeats this 5 times, with the control flow looping and calling functions multiple times through various execution paths. This can be done due to a lack of experience, the use of AI, or the intention to obfuscate the malware’s main functionality.
  • T1489 – Service Stop
    After the data is encrypted, it proceeds to stop all processes. It accomplishes this by executing “terminate processes,” which is hard-coded to include 50 common processes and services, such as taskmgr, eventlog, python, winmgmt, and many other software applications. This technique makes the system practically unusable, impacting the organization’s operations.
  • T1490 – Inhibit System Recovery
    Its final step is to recursively loop through all directories and files, deleting any shadow copy backups. This impacts the organization by deleting all necessary backups to restore normal operation.
  • TA0010 – Exfiltration
    If the ransom is not paid, all data will be exfiltrated and sold to third parties

V. Recommendations

  • Implement a Defense-In-Depth Strategy:
    • Implement many different layers of security. FunkSec is known for using phishing campaigns and exploiting vulnerabilities. Implement proper email security, such as filters and phishing detection software, and enable multifactor authentication. Security awareness training and regular updates or patches across all systems will also help prevent ransomware attacks like FunkSec’s. Other layers to implement include Endpoint Detection and Response (EDR) software, firewalls, and robust Anti-Virus (AV) to all devices and systems.
  • Perform Regularly Scheduled Backups & Audits:
    • Perform both online and offline backups. Performing both will ensure that copies of data are in various locations, one of which is inaccessible to the attacker. Regular security audits are essential to stay ahead of security vulnerabilities by identifying potential weakness ransomware can exploit and patching accordingly.
  • Monitor for Compromise Indicators (IoCs):
    • Check network traffic and system logs frequently for known IoCs associated with this attack, such as file paths, flagged IP addresses, MD5 hash values, and log entries that may indicate exploitation (see the IoCs section for references). To improve detection capabilities, incorporate these IoCs into SIEM or IDS/IPS systems.
  • Establish an Incident Response Plan:
    • Create or revise an incident response plan that includes steps to handle the FunkSec ransomware. The reaction team is equipped and trained to handle any potential ransomware breaches.
  • Isolate Compromised Systems:
    • Isolate compromised systems right away to stop additional access or harm if any indications of compromise are found. Notify the affected parties and conduct a comprehensive investigation to eliminate any malware or backdoors.

VI. IOCs (Indicators of Compromise)

 

Type Indicator
SHA-256 Hash

c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c

SHA-256 Hash

66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd

SHA-256 Hash

dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac

SHA-256 Hash b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb
SHA-256 Hash 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd
SHA-256 Hash e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22
SHA-256 Hash 20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d
SHA-256 Hash dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966
SHA-256 Hash 7e223a685d5324491bcacf3127869f9f3ec5d5100c5e7cb5af45a227e6ab4603
Source Code File *ransomware.rs*
File Extension (.funksec)
FunkSec Scorpion Domain hxxps://miniapps[.]ai/funksec
FunkSec Malware Hosting hxxps://gofile[.]io/d/8FOSeP
FunkSec DLS hxxp://funknqn44slwmgwgnewne6bintbooauwkaupik4yrlgtycew3ergraid[.]onion/
FunkSec DLS hxxp://funkiydk7c6j3vvck5zk2giml2u746fa5irwalw2kjem6tvofji7rwid[.]onion/

 

VII. Additional OSINT Information

Associated Threat Actors:

Scorpion: Prominent member of FunkSec, uses multiple aliases such as DessertStorm.

El_farado: Promotes FunkSec, making sure this group stays visible.

Associated Hacktivist Groups:

-Ghost Algeria: Made evident in a ransom note similar to FunkSec’s.

-Cyb3r Fl00d: Old group based on a screenshot.

Artificial Intelligence (AI) Indicators:

-Very well structured and formatted comments and code, as well as the publication of an AI chatbot named Scorpion.

VIII. References

Dulaunoy, A., Fafner, & Harper, T. (n.d.). RansomLook . RansomLook. https://www.ransomlook.io/

Antoniuk, D. (2025, January 10). New amateurish ransomware group FunkSec using AI to develop malware. Cyber Security News | The Record. https://therecord.media/funksec-ransomware-using-ai-malware

Arghire, I. (2025, January 13). Emerging FUNKSEC ransomware developed using AI. SecurityWeek. https://www.securityweek.com/emerging-funksec-ransomware-developed-using-ai/

Check Point Research. (2025, January 9). Meet FunkSec: A new, surprising ransomware group, powered by ai. Check Point Blog. https://blog.checkpoint.com/research/meet-funksec-a-new-surprising-ransomware-group-powered-by-ai/

Check Point Software. (2024, February 8). What is double extortion ransomware?. Check Point Software. https://www.checkpoint.com/cyber-hub/ransomware/what-is-double-extortion-ransomware/

FunkSec RaaS Dominates the Ransomware Landscape in December. Cyber.nj.gov. (2025, January 16). https://www.cyber.nj.gov/Home/Components/News/News/1574/214?rq=emotet

FUNKSEC ransomware. Broadcom Inc. (2025, January 9). https://www.broadcom.com/support/security-center/protection-bulletin/funksec-ransomware

Hollingworth, D. (2025, January 14). Inside FunkSec, the self-taught hackers supported by Ai Code. Cyber Daily. https://www.cyberdaily.au/security/11575-inside-funksec-the-self-taught-hackers-supported-by-ai-code

Infosecurity Magazine. (2025, January 13). New Ransomware Group uses AI to develop Nefarious Tools. Infosecurity Magazine. https://www.infosecurity-magazine.com/news/new-ransomware-group-uses-ai/

Lakshmanan, R. (2025, January 11). Ai-driven ransomware FUNKSEC targets 85 victims using double extortion tactics. The Hacker News. https://thehackernews.com/2025/01/ai-driven-ransomware-funksec-targets-85.html

LevelBlue – Open Threat Exchange. LevelBlue Open Threat Exchange. (n.d.). https://otx.alienvault.com/pulse/678127dbf6bb4958da4254cd/

MalwareBazaar Database-funksec. MalwareBazaar. (2025). https://bazaar.abuse.ch/browse/tag/funksec/

Meskauskas, T. (2025, January 13). Funklocker (FunkSec) ransomware. FunkLocker (FunkSec) Ransomware – Decryption, removal, and lost files recovery (updated). https://www.pcrisk.com/removal-guides/31853-funklocker-funksec-ransomware

Mitre ATT&CK®. MITRE ATT&CK®. (n.d.). https://attack.mitre.org/

Price, A. (2024, December 4). Take me down to FUNKSEC town: Funksec ransomware DLS Emergence . CYJAX. https://www.cyjax.com/resources/blog/take-me-down-to-funksec-town-funksec-ransomware-dls-emergence/

Reynolds, I. (2025, January 11). FUNKSEC: The emergence of ai-driven ransomware threats. SecureTeam. https://secureteam.co.uk/news/funksec-the-emergence-of-ai-driven-ransomware-threats/

Stcpresearch. (2025, January 10). FunkSec – alleged top ransomware group powered by ai. Check Point Research. https://research.checkpoint.com/2025/funksec-alleged-top-ransomware-group-powered-by-ai/

Tag funksec. ThreatFox. (n.d.). https://threatfox.abuse.ch/browse/tag/funksec/

Check Point Research. (2025, January 15). FunkSec: The rising yet controversial ransomware threat actor dominating December 2024. Check Point Blog. https://blog.checkpoint.com/research/funksec-the-rising-yet-controversial-ransomware-threat-actor-dominating-december-2024/

Contributing Security Analysts: Timothy Kircher

Other posts of interest...

Malware Campaign Exploits Microsoft Dev Tunnels

1 min read

Malware Campaign Exploits Microsoft Dev Tunnels

Originally Published March 31, 2025

Read More
SparkRAT: A Multi-Platform Remote Access Tool

1 min read

SparkRAT: A Multi-Platform Remote Access Tool

Originally Published March 4, 2025

Read More
Qilin Ransomware – A Double Extortion Campaign

1 min read

Qilin Ransomware – A Double Extortion Campaign

Originally Published December 8, 2025

Read More