Funksec is a newly identified extortion group that has
claimed 11 victims across various sectors, including media, IT, and education,
operating a Tor-based DLS to centralize its ransomware activities. The group
advertises a free DDoS tool and may develop its own ransomware binary,
indicating significant technical capability. The DLS was likely created in late
November to early December 2024, with the first advertisement titled “Funksec
Ransomware” posted on 3 December 2024. Currently, there is limited publicly
available information on Funksec\'s TTPs, and it is not known to be associated
with any other threat groups.
FunkSec is an AI-assisted
ransomware-as-a-service (RaaS) group that emerged in late 2024 and
rapidly gained notoriety for claiming over 120 victims across
industries including government, healthcare, and finance. The group
is characterized by its double extortion tactics, combining data
encryption with theft, and its use of hacktivist rhetoric alongside
financially motivated attacks.
Key operational details include:
- Malware: The
group uses FunkLocker, a Rust-based ransomware
that encrypts files using ChaCha20 and appends the .funksec extension. - AI
Integration: FunkSec leverages Generative AI to
assist in malware development, phishing template creation, and code
refinement, lowering the barrier for less experienced actors. - Access
Methods: Initial access is typically gained through phishing
emails, credential stuffing, and exploiting unpatched
vulnerabilities in exposed systems like RDP and VPNs. - Extortion
Strategy: The group demands unusually low ransoms (sometimes
as low as $10,000) and additionally sells stolen data to third
parties at discounted prices on dark web markets. - Geographic
Base: Technical analysis suggests the primary developer is likely
based in Algeria, with the group targeting organizations in
the U.S., India, Spain, and Mongolia.
FunkSec\'s \"discovery\" spans several milestones
rather than a single date:
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Date | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt .5in 6.0pt 9.0pt\"> Event |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> October 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> First public introduction — actor \"Scorpion\" |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Late Nov – Early Dec 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Data Leak Site (DLS) created (Malpedia estimates late |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> December 3, 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> First advertisement titled \"Funksec Ransomware\" |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> December 4, 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> First victims published on the DLS (data |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> December 15, 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Initial Rust source code (ransomware.rs) uploaded to |
December 31, 2024 | First known FunkLocker ransomware binary sample |
So the most commonly cited \"discovery\" date
is early December 2024 (when the DLS went live and victims
started appearing), though the group\'s name first surfaced publicly in October
2024. Some reports also note possible operational activity as
early as September 2024, but this is unconfirmed.
