National Cyber Warfare Foundation (NCWF)

Cross-border Dark Horse Tops Two Charts! Shengshu Technology Launches MotuBrain, Defining a New Standard for Embodied Intelligence Brain


0 user ratings
2026-09-01 18:43:25
error

https://news.aibase.com/news/27628



Cross-border Dark Horse Tops Two Charts! Shengshu
Technology Launches MotuBrain, Defining a New Standard for Embodied
Intelligence Brain



aibase



Published in Latest AI News



Time :Apr 30, 2026



Read :5minute



The identity of the "mysterious model" that has
been lingering in the field of embodied intelligence for three weeks has
finally been revealed. Previously, a model named MotuBrain quietly
topped two major international benchmarks for physical world understanding and
action execution, sparking widespread speculation in the industry.
Recently, Shengshu Technology, which has gained fame through the video
large model Vidu, officially announced that this model is its latest commercial
achievement in the field of embodied intelligence.



This "cross-border" effort is no mere experiment.
MotuBrain set new records in WorldArena (assessing physical world
understanding) and RoboTwin 2.0 (assessing action execution). Especially in
complex environments with simulated random disturbances, it was the only model
to achieve an average score above 95, demonstrating strong generalization
capabilities.





"See and Act": Breaking the Boundaries Between
Perception and Action



Differing from traditional "imagine first, then
act" models, MotuBrain adopts an innovative "World Action
Model" approach. This "see and act" design allows robots to
simulate while making decisions, ensuring that prediction and execution errors
do not amplify each other, greatly improving response speed.



In practical demonstrations, the robot equipped with this
system showed a high level of intelligence. In a hot pot scenario, the robot
could visually determine if the spoon was empty and decide autonomously whether
to retrieve it again, rather than rigidly repeating preset actions. This
"reading the room" ability marks the transition of robots from simple
mechanical execution to true intelligent decision-making.





One Brain, Multiple Forms: Smooth Integration of
Long-Term Tasks



The core advantage of MotuBrain lies in its strong
versatility. It not only supports "one brain, multiple forms,"
adapting to different degrees of freedom and sensor-equipped robot bodies, but
also possesses long-term task processing capabilities. In demonstrations such
as flower arranging, mixing cocktails, and tidying up the sofa, the robot can
complete more than 10 atomic actions continuously, with a smooth process
requiring no human intervention.



Data shows that as the variety of tasks increases, the
learning success rate of MotuBrain tends to rise. This indicates that
the model has mastered the universal underlying laws of the physical world,
rather than memorizing action templates. The more diverse the tasks, the better
its performance.



Establishing a Presence in the Physical World, Pursuing
Dual Tracks of Digital and Physical Realms



The strength demonstrated by Shengshu
Technology stems from its deep technical foundation. Through the
world-first U-ViT architecture, the company achieved unification between
digital world generation (VGM) and physical world execution (WAM). On one
hand, Vidu generates virtual worlds, while on the
other, MotuBrain drives physical interactions. This dual-track
strategy gives it a significant advantage in data acquisition costs and model
iteration speed.





Currently, Shengshu Technology
has reached strategic partnerships with several companies, including WuJie
Dynamics and XingChen Intelligence. As the focus of competition in embodied
intelligence shifts, model developers with a general-purpose "brain"
are becoming key forces in reshaping the industry landscape.





Funksec is a newly identified extortion group that has
claimed 11 victims across various sectors, including media, IT, and education,
operating a Tor-based DLS to centralize its ransomware activities. The group
advertises a free DDoS tool and may develop its own ransomware binary,
indicating significant technical capability. The DLS was likely created in late
November to early December 2024, with the first advertisement titled “Funksec
Ransomware” posted on 3 December 2024. Currently, there is limited publicly
available information on Funksec's TTPs, and it is not known to be associated
with any other threat groups.



 



 



FunkSec is an AI-assisted
ransomware-as-a-service (RaaS)
group that emerged in late 2024 and
rapidly gained notoriety for claiming over 120 victims across
industries including government, healthcare, and finance.  The group
is characterized by its double extortion tactics, combining data
encryption with theft, and its use of hacktivist rhetoric alongside
financially motivated attacks. 



Key operational details include:




  • Malware: The
    group uses FunkLocker, a Rust-based ransomware
    that encrypts files using ChaCha20 and appends the .funksec extension. 

  • AI
    Integration:
    FunkSec leverages Generative AI to
    assist in malware development, phishing template creation, and code
    refinement, lowering the barrier for less experienced actors. 

  • Access
    Methods:
    Initial access is typically gained through phishing
    emails
    , credential stuffing, and exploiting unpatched
    vulnerabilities
    in exposed systems like RDP and VPNs. 

  • Extortion
    Strategy:
    The group demands unusually low ransoms (sometimes
    as low as $10,000) and additionally sells stolen data to third
    parties at discounted prices on dark web markets. 

  • Geographic
    Base:
    Technical analysis suggests the primary developer is likely
    based in Algeria, with the group targeting organizations in
    the U.S., India, Spain, and Mongolia



What are the specific indicators of FunkLocker malware?



FunkLocker (FunkSec) — Specific Indicators of Compromise



File Hashes (SHA-256)

















































Hash



Description



c233aec7917cf34294c19dd60ff79a6e0fac5ed6f0cb57af98013c08201a7a1c



FunkLocker ransomware executable



e29d95bfb815be80075f0f8bef4fa690abcc461e31a7b3b73106bfcd5cd79033



Ransom note file



66dbf939c00b09d8d22c692864b68c4a602e7a59c4b925b2e2bef57b1ad047bd



Additional sample



dcf536edd67a98868759f4e72bcbd1f4404c70048a2a3257e77d8af06cb036ac



Additional sample



b1ef7b267d887e34bf0242a94b38e7dc9fd5e6f8b2c5c440ce4ec98cc74642fb



Additional sample



5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd



Additional sample



e622f3b743c7fc0a011b07a2e656aa2b5e50a4876721bcf1f405d582ca4cda22



Additional sample



20ed21bfdb7aa970b12e7368eba8e26a711752f1cc5416b6fd6629d0e2a44e5d



Additional sample



dd15ce869aa79884753e3baad19b0437075202be86268b84f3ec2303e1ecd966



Additional sample



7e223a685d5324491bcacf3127869f9f3ec5d5100c5e7cb5af45a227e6ab4603



Additional sample




File & Artifact Indicators




  • Encrypted
    file extension:
    .funksec

  • Ransom
    note names:
    README-[random_string].md, readme.txt (e.g., README-ZasRvdSR44.md)

  • Source
    code artifact:
    *ransomware.rs* (Rust source)

  • Hardcoded
    strings in binary:
    RansomwarePassword123, "device has
    been successfully infiltrated by funksec ransomware!" 



Network / Infrastructure IOCs





























Type



Indicator



Scorpion (leak site)



hxxps://miniapps[.]ai/funksec



Malware hosting



hxxps://gofile[.]io/d/8FOSeP



Darknet leak site



hxxp://funknqn44slwmgwgnewne6bintbooauwkaupik4yrlgtycew3ergraid[.]onion/



Darknet leak site



hxxp://funkiydk7c6j3vvck5zk2giml2u746fa5irwalw2kjem6tvofji7rwid[.]onion/



BTC wallet



Reused across victims (~$3,000 total transactions)




Behavioral / Command-Line IOCs



These are the specific commands FunkLocker executes
via living-off-the-land tools:


















































Tool



Command



Purpose



PowerShell



Set-MpPreference -DisableRealtimeMonitoring



Disable Windows Defender



PowerShell



Set-ExecutionPolicy Bypass -Scope Process



Allow unrestricted script execution



wevtutil.exe



wevtutil sl Security /e:false



Disable Security event logging



wevtutil.exe



wevtutil sl Application /e:false



Disable Application event logging



vssadmin.exe



vssadmin delete shadows /all /quiet



Delete Volume Shadow Copies



taskkill.exe



taskkill /F /IM



Force-terminate Office, browsers, etc.



sc.exe



sc stop



Stop Windows services



net.exe



Network share/session discovery



Reconnaissance




MITRE ATT&CK Mapping









































Technique ID



Technique



T1036.005



Masquerading: Match Legitimate Resource Name or Location



T1486



Data Encrypted for Impact



T1490



Inhibit System Recovery



T1489



Service Stop



T1059.001



Command and Scripting Interpreter: PowerShell



T1135



Network Share Discovery



T1562.001



Defense Evasion: Disable or Modify Tools



T1569.002



Service Execution: Service Commands




YARA Rule (for endpoint scanning) 



rule funklocker_ransomware {



   meta:



      description =
"Detects Funklocker ransomware or similar variants"



      author =
"Oluwaseyi Soneye"



      reference =
"Strings output analysis"



      date =
"2025-11-10"



 



   strings:



      $x1 =
"Set-MpPreference -DisableRealtimeMonitoring" nocase



      $x2 =
"wevtutil sl Security /e:false" nocase



      $x3 =
"wevtutil sl Application /e:false" nocase



      $x4 =
"Set-ExecutionPolicy Bypass -Scope Process" nocase



      $x5 =
"Set-MpPreference -DisableRealtimeMonitoring $truewevtutil sl Security
/e:falsewevtutil sl Application /e:falseSet-ExecutionPolicy" nocase



      $x6 =
"vssadmindelete shadows/all/quiet" nocase



      $x7 =
"taskkill/F/IM" nocase



      $x8 =
"RansomwarePassword123" nocase



      $x9 =
"device has been successfully infiltrated by funksec ransomware!"
nocase



      $x10 =
"funksec" nocase



   condition:



      uint16(0) ==
0x5a4d and



        (



          (5 of ($x1,
$x2, $x3, $x4, $x5, $x6, $x7)) or



          (2 of ($x8,
$x9, $x10))



        )



}



Note: Avast Labs released a public
decryptor
for FunkLocker victims due to the group's weak operational
security (reused BTC wallets and hardcoded keys).  The No
More Ransom
portal also provides recovery guidance. 



 



What are the symptoms of infection?



Symptoms of a FunkLocker Infection



Immediate / User-Visible Symptoms




  • Files
    encrypted
    with the .funksec extension
    (e.g., report.pdf → report.pdf.funksec)

  • Desktop
    wallpaper turns black
    (Shell Experience Host service is
    terminated)

  • Ransom
    note
    (README-[random_string].md) dropped on the desktop — though
    due to system instability, victims often cannot see it until after
    a reboot

  • Applications
    crash or stop working
    — the malware force-terminates ~50 common
    processes (Office, browsers, taskmgr, etc.)

  • System
    becomes largely unusable
    — services are stopped, leaving the OS
    in a broken state 



System-Level Symptoms (observable in logs / monitoring)





































Symptom



What's happening



Windows Defender real-time protection disabled



Set-MpPreference -DisableRealtimeMonitoring



Security & Application event logs disabled



wevtutil sl Security /e:false



Volume Shadow Copies deleted



vssadmin delete shadows /all /quiet



Multiple processes/services force-killed



taskkill /F /IM, sc stop



PowerShell execution policy set to Bypass



Set-ExecutionPolicy Bypass -Scope Process



Sudden network slowdowns



Encryption of files across network shares



Unusual outbound connections



Data exfiltration to attacker infrastructure




Post-Encryption / Extortion Phase




  • Within 24–48
    hours
    , a leak site posting appears on the dark web
    (.onion), threatening to publish exfiltrated data

  • Ransom
    note directs the victim to a Tor site with a unique victim ID and
    a Bitcoin wallet address

  • Payment
    deadline of 3–5 days is typically stated

  • The
    note warns against contacting authorities, using antivirus, or modifying
    the system 



Important Context



Threat actors typically infiltrate the system 2–4
weeks before
encryption occurs.  By the time visible
symptoms appear, data has already been exfiltrated.  The encryption
event itself is fast (local-only, no C2 callback), but the overall attack
timeline spans weeks. 



Antivirus Detections (at execution time)




  • Microsoft: Trojan:Win32/Wacatac.B!ml

  • Kaspersky: Trojan.Win32.DelShad.myd

  • ESET: A
    Variant Of Generik.GZBNBIS



If any of these symptoms are observed, the recommended
immediate actions are: disconnect from the network, do not reboot
or restore from backups (to preserve forensic evidence), and engage an incident
response team. 



What specific malware families are similar to FunkLocker?



Malware Families Similar to FunkLocker



Similarity depends on which axis you're comparing. Here are
the closest matches by shared characteristic:



Rust-Based Ransomware (same language)




























































Family



Key Similarity



Notable Difference



BlackCat (ALPHV)



Rust, ChaCha20 encryption, RaaS, double/triple extortion,
cross-platform



Far more mature, API-driven negotiation portal, triple
extortion (DoS)



Cicada3301



Rust, ChaCha20, cross-platform (Win/Linux/ESXi/NAS/PowerPC),
similar config interfaces to BlackCat



Emerged mid-2024, more polished



Hive



Rust (ported from Go), double extortion



Windows-only, older, less active



Nokoyawa



Rust (v2.0, 2022), double extortion, ECC encryption



Originally C, ported to Rust; Windows-only



Qilin (Agenda)



Rust (ported from Go), double extortion, RaaS, most active
group of 2025



More established, broader victimology



3AM (ThreeAM)



Rust, VSS deletion, service stopping, double extortion,
used as LockBit fallback



Simpler, 64-bit only, less sophisticated



Luna



Rust, cross-platform (Win/Linux/ESXi), Curve25519 + AES



Russian-speaking affiliates, simpler structure



01flip



Rust, multi-platform (Win/Linux), double extortion



Newer (2025), possible LockBit overlap



Embargo



Rust, suspected rewrite of ALPHV code



Less active



RALord



Rust ransomware (reported 2025)



Limited public detail




AI-Assisted / AI-Generated Code (same development
pattern)





























Family



Similarity



PromptLocker



AI-generated ransomware (educational demo, not malicious)



Koske



AI-generated Linux-targeting malware



CyberLock



AI-themed lures for distribution



Lucky_Gh0$t



AI-themed lures



Numero



AI-themed lures




Local-Only Encryption (no C2 callback during encryption)













Family



Similarity



Mamona



Entirely local encryption, no network callback — same
operational pattern as FunkLocker




Shared TTPs (defense evasion + disruption)



Families that share FunkLocker's specific "disable AV →
disable logging → delete VSS → kill processes → encrypt" kill chain:




  • LockBit
    3.0 — same VSS deletion, service stopping, but far more sophisticated
    (AES-256 + RSA-2048, self-propagating)

  • Phobos —
    similar TTPs, uses Smokeloader/Cobalt Strike/Mimikatz, targets public
    sector

  • Black
    Basta — Conti code lineage, double extortion, service disruption

  • RansomHub —
    dominant post-LockBit RaaS, double extortion 



Closest Overall Analogue



BlackCat/ALPHV is the most frequently cited
comparison point: both are Rust, both use ChaCha20, both operate as RaaS with
double/triple extortion, and both target cross-platform
environments.  The key distinction is that BlackCat is a mature,
well-funded operation while FunkLocker is a low-skill, AI-assisted operation
with inconsistent code quality and weaker operational security (reused wallets,
hardcoded keys).



Cicada3301 is technically the closest match —
Rust + ChaCha20 + cross-platform + similar configuration patterns — but it
emerged independently and is more polished. 



What specific AI tools generated FunkLocker's code?



Specific AI Tools Used to Generate FunkLocker's Code



The short answer: no single specific LLM model has
been definitively identified
as the code
generator.  Researchers consistently refer to "LLM agents"
generically. However, two specific tools/platforms have been confirmed:



Confirmed Tools

















Tool



Role



Miniapps



Platform used to build a custom AI chatbot ("Scorpion")
specifically for malicious operations.  Chosen because it lacks the
safety restrictions of mainstream tools like ChatGPT. Used for code
generation and operational support.



ChatGPT



Used to generate summaries of the
ransomware's capabilities — the group uploaded the binary to ChatGPT and
posted the output on their leak site as a form of "AI
interpretation" of their own code. 




What Researchers Could NOT Confirm



The actual code-generating LLM (the one that
produced the Rust source in ransomware.rs) was never pinned to a specific
model (e.g., GPT-4, Claude, Llama, etc.). The evidence points to a generic
"LLM agent" workflow:




  • "Ask
    AI → Get snippet → Paste snippet" development cycle (ANY.RUN)

  • Perfect
    English code comments vs. very basic English in the group's other
    communications (Check Point, Kaspersky, CSO Online)

  • Generic
    placeholder comments like "placeholder for actual check" (Kaspersky)

  • Technical
    inconsistencies — commands for different operating systems mixed in the
    same file (Kaspersky, Red Hot Cyber)

  • Declared
    but unused functions and modules (Kaspersky)

  • Redundant
    call functions and repeating control flow (Check Point)

  • Seven
    distinct builds compiled in six days — a pace consistent with prompt-based
    iteration rather than manual development (Palo Alto Unit 42, August
    2026) 





 



Summary



The Miniapps platform is
the only specifically named tool tied to code generation.  The
underlying LLM model behind Miniapps' output was not disclosed or fingerprinted
by any researcher. ChatGPT was used for
documentation/summarization, not for generating the Rust source itself. The
development pattern is best described as "vibecoding"
iterative prompting with an LLM to produce and patch code fragments without
deep understanding of the output. 



What is the Miniapps platform?



Miniapps.ai



Miniapps.ai is
a no-code AI app builder and marketplace, launched in May
2023
and based in San Francisco, CA (~10
employees).  It lets anyone create, publish, and share small
AI-powered "mini apps" — essentially prompt templates wired
to user inputs
and backed by a choice of LLMs. 



How It Works








  1. Pick a model
    GPT-4o, Claude, Gemini, Grok, DeepSeek, or image models (Flux, etc.)

  2. Define prompt logic
    write system instructions and input fields via a visual editor (no coding)

  3. Publish instantly
    the mini-app gets a shareable URL; others can use or clone it 







What It Hosts



The platform functions as both
a builder and a discovery catalogue (think
"app store for AI micro-tools").  Community-created apps
span:








  • Chatbots & roleplay
    characters

  • SEO / marketing / social
    media generators

  • Image generation & face
    swap

  • Language tutors, AI
    therapists

  • Games, simulators, coding
    assistants

  • Productivity utilities
    (calculators, form tools) 







Pricing



Freemium — free tier
for basic usage; premium credits unlock higher usage limits or access to more
advanced models. 



Relevance to FunkSec



The FunkSec group used Miniapps.ai
to build "Scorpion", a custom AI chatbot hosted
at miniapps[.]ai/funksec. Researchers noted the platform was chosen
because it lacks the content-safety guardrails of mainstream
tools like ChatGPT, making it easier to build an uncensored assistant for code
generation and operational support without triggering refusals. This mirrors a
broader pattern of threat actors exploiting permissive no-code AI platforms to
lower the barrier to building malware tooling. 



FunkSec Domain &
Infrastructure Indicators



A key point: FunkLocker
has no traditional C2 domains
— the encryption is entirely local with
no callback.  The group's web infrastructure is limited to leak
sites, a chat server, and a few hosting/delivery URLs
, mostly on Tor. 



Tor (.onion) Domains









































































Domain





Purpose





Status (as of recent scan)





funkxxkovrk7ctnggbjnthdajav4ggex53k6m2x3esjwlxrkb3qiztid[.]onion





Data Leak Site (DLS)





Up (~40% uptime 30d)





funknqn44slwmgwgnewne6bintbooauwkaupik4yrlgtycew3ergraid[.]onion





DLS (previous)





Down (~27% uptime)





funkiydk7c6j3vvck5zk2giml2u746fa5irwalw2kjem6tvofji7rwid[.]onion





DLS (previous)





Down (~23% uptime)





funk4ph7igelwpgadmus4n4moyhh22cib723hllneen7g2qkklml4sqd[.]onion





FunkForum (affiliate
forum)





Down





funkhnsbaxojjjju65bhc7xuidjwvmwhdmgarvhbhs3szqkpzkmvnvid[.]onion





FunkBID (data
auction)





Down





funk45xqgrkrtej4743evcgv65oi3w4shwvjx3cvrdtqwul7gzkxuxqd[.]onion





Chat/Negotiation server





Down





funksec53xh7j5t6ysgwnaidj5vkh3aqajanplix533kwxdz3qrwugid[.]onion





DLS v3.0





Down





funksecsekgasgjqlzzkmcnutrrrafavpszijoilbd6z3dkbzvqu43id[.]onion





DLS (previous)





Down





funkyiazgfsrxrib6rnxbhkgfqi7isisfbqnwk2ycf7tpgfhtevlamad[.]onion





DLS (previous)





Down





pke2vht5jdeninupk7i2thcfvxegsue6oraswpka35breuj7xxz2erid[.]onion





DLS (previous)





Down





ykqjcrptcai76ru5u7jhvspkeizfsvpgovton4jmreawj4zdwe4qnlid[.]onion





DLS (previous)





Down





7ixfdvqb4eaju5lzj4gg76kwlrxg4ugqpuog5oqkkmgfyn33h527oyyd[.]onion





DLS (previous)





Down







Clearnet Domains & URLs

































Domain / URL





Purpose





Notes





funksec[.]top





Clearnet leak site mirror





Down; was hosted on "Anon
Hosting"





miniapps[.]ai/funksec





Scorpion AI chatbot





The Miniapps-hosted AI assistant
used for code generation





gofile[.]io/d/8FOSeP





Malware binary hosting





Distribution of FunkLocker
samples





176.113.115[.]19





Naked IP dropper





Delivered ScreenUpdateSync.exe (dropper)







Other Referenced Infrastructure








  • ip-api[.]com
    referenced in some samples (likely for geolocation/lookup, not
    attacker-controlled)

  • i[.]imgur[.]com
    image hosting referenced in some samples (abuse of legitimate service)







What Does NOT Exist








  • No dedicated C2 domains
    the malware never phones home during encryption

  • No DGA (Domain Generation
    Algorithm)
    — despite some low-quality AI-generated articles
    claiming an "AI-assisted DGA," no researcher has identified
    one.  The group's infrastructure is simple and static

  • No fast-flux or rotating
    domain patterns
    — the .onion addresses are fixed per instance,
    just rotated when taken down







Summary



FunkSec's web footprint is minimal
and mostly dead
. The group relies on a small set of rotating .onion leak
sites (currently only one is up), a single clearnet domain (funksec.top, down),
and the Miniapps.ai chatbot. The absence of C2 infrastructure is a defining
characteristic — it's both a limitation (no remote control, no key retrieval
channel) and a byproduct of the AI-generated, low-skill development approach.


















Domain





Purpose





Status





funksec.top





Clearnet mirror of the Data Leak
Site





Down (hosted on
"Anon Hosting – Hidden Services"; last checked 2025-07-05)







Everything else in their clearnet
footprint is a subpath on a third-party platform, not a domain they
own:




























URL





Platform





Purpose





miniapps.ai/funksec





Miniapps.ai





Scorpion AI chatbot





gofile.io/d/8FOSeP





GoFile





Malware binary distribution





fastupload.com/...





FastUpload





Leak data downloads







And one naked IP used
as a dropper:
















IP





Purpose





176.113.115.19





Delivered ScreenUpdateSync.exe (dropper)







Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.